Junglewise Threat Intelligence

CVE-2026-27964: NeoRazorX FacturaScripts reflected XSS in fsNick cookie

CVE-2026-27964 · Severity: low · CVSS 3.9 · Published 2026-05-18

Technologies: NeoRazorX FacturaScripts, facturascripts/facturascripts (Packagist). Vendors: NeoRazorX, Packagist.

Executive brief

FacturaScripts, an open-source ERP and accounting system, is vulnerable to a security flaw where user-controlled data in a browser cookie is displayed back to the user without proper safety checks. An attacker who can manipulate a user's cookies could execute malicious scripts in the victim's browser session. While the system attempts to log the user out when it detects the manipulation, the malicious script can still run briefly, potentially allowing for unauthorized actions or data theft before the session ends.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in FacturaScripts versions up to 2025.71. The application reflects the value of the 'fsNick' cookie directly into the DOM without proper sanitization or encoding. Although the server-side logic identifies the modified session and triggers a logout redirect, the malicious payload is rendered in the HTML and executed by the browser before the redirect is processed. An attacker with the ability to manipulate cookies (e.g., via local access or other web vulnerabilities) can execute arbitrary JavaScript in the context of the user's session. A fix is available in the project's source repository.

Affected products

  • NeoRazorX FacturaScripts <= 2025.71

Timeline

  • 2026-05-07: disclosed
  • 2026-05-07: advisory
  • 2026-05-18: other: NVD published

References

Related threats