Executive brief
FacturaScripts is an open-source ERP and accounting system. A vulnerability in its CSV export feature allows low-privileged users (such as sales or accounting staff) to inject malicious formulas into data fields like customer names or product descriptions. When an administrator later exports this data to a CSV file and opens it in a spreadsheet application like Excel or LibreOffice, the malicious code can execute on the administrator's computer, potentially leading to full system takeover or data theft.
Technical details
A CSV formula injection vulnerability exists in FacturaScripts due to insufficient sanitization of leading characters in the CSVExport class. The `CSVExport::writeData()` method in `Core/Lib/Export/CSVExport.php` fails to neutralize characters that trigger formula execution in spreadsheet software (e.g., `=`, `+`, `-`, `@`). While the application sanitizes HTML characters, it does not address spreadsheet meta-characters. An authenticated low-privileged attacker can input a malicious payload (such as a DDE command) into a model field (e.g., Cliente, Producto). When an administrator triggers a CSV export via the `?action=export&option=CSV` controller, the payload is included verbatim. Opening the resulting file in Excel or LibreOffice can lead to arbitrary command execution or data exfiltration from the administrator's workstation.
Affected products
- NeoRazorX FacturaScripts <= 2026.1
Timeline
- 2026-04-30: other: PoC verified against master branch
- 2026-07-14: advisory: GitHub Advisory published