Unauthorized Account Modification in FacturaScripts by NeoRazorX
CVE-2026-32699

5.3MEDIUM

Key Information:

Vendor

Neorazorx

Vendor
CVE Published:
5 May 2026

What is CVE-2026-32699?

FacturaScripts, an open-source accounting and invoicing software, is susceptible to an improper input validation vulnerability. In versions 2025.92 and earlier, the application fails to adequately validate the 'nick' parameter when processing POST requests to the EditUser controller. Although the user interface restricts editing this field under normal circumstances, an attacker with basic technical skills can intercept and modify the request. This manipulation allows the unauthorized editing of the 'nick' field, which could include the modification of administrator accounts, leading to unauthorized access and potential control over the system.

Affected Version(s)

facturascripts <= 2025.92

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.