Unauthorized Account Modification in FacturaScripts by NeoRazorX
CVE-2026-32699
5.3MEDIUM
What is CVE-2026-32699?
FacturaScripts, an open-source accounting and invoicing software, is susceptible to an improper input validation vulnerability. In versions 2025.92 and earlier, the application fails to adequately validate the 'nick' parameter when processing POST requests to the EditUser controller. Although the user interface restricts editing this field under normal circumstances, an attacker with basic technical skills can intercept and modify the request. This manipulation allows the unauthorized editing of the 'nick' field, which could include the modification of administrator accounts, leading to unauthorized access and potential control over the system.
Affected Version(s)
facturascripts <= 2025.92
