Junglewise Threat Intelligence

CVE-2026-42879: FacturaScripts unrestricted file upload in product image upload

CVE-2026-42879 · Severity: medium · CVSS 6.3 · Published 2026-05-27

Technologies: NeoRazorX FacturaScripts, facturascripts/facturascripts (Packagist). Vendors: NeoRazorX, Packagist.

Executive brief

FacturaScripts, an open-source ERP and accounting system, contains a vulnerability in its product image upload feature. An authenticated user can bypass security checks to upload malicious PHP scripts disguised as images. If successful, an attacker can remotely execute commands on the server, potentially leading to a full system takeover, data theft, or service disruption.

Technical details

An authenticated unrestricted file upload vulnerability exists in the `addImageAction()` method of `Core/Lib/ExtendedController/ProductImagesTrait.php`. The application validates file uploads by checking if the MIME type contains the string 'image/', which can be spoofed by prepending GIF89a magic bytes to a PHP payload. Because the system preserves the original file extension and stores the file in a web-accessible directory (`/MyFiles/YYYY/MM/`), an attacker can upload a `.php` file and execute it via a direct URL request. This results in Remote Code Execution (RCE) with the privileges of the web server user.

Affected products

  • NeoRazorX FacturaScripts <= 2025.81

Timeline

  • 2026-05-07: advisory: GitHub Advisory published
  • 2026-05-27: disclosed: NVD publication date

References

Related threats