Executive brief
FacturaScripts, an open-source ERP and CRM platform, is vulnerable to a security flaw in its file upload system. An authenticated user can bypass intended storage restrictions to write files anywhere on the server's disk. This allows an attacker to take full control of the server by uploading and executing malicious code, potentially leading to data theft or complete service disruption.
Technical details
A path traversal vulnerability exists in the `FacturaScripts\Core\UploadedFile::move()` method. The application fails to sanitize the client-provided filename from `getClientOriginalName()` before concatenating it with the destination directory. An authenticated attacker can use `../` sequences to write files outside the intended `MyFiles/` directory. By targeting directories excluded from the default `index.php` rewrite rules (such as `Dinamic/Assets/`) and uploading a malicious `.htaccess` file to remap file extensions to the PHP handler, an attacker can achieve remote code execution (RCE). The vulnerability affects multiple API and UI upload endpoints.
Affected products
- NeoRazorX FacturaScripts >= 2025, <= 2026.2
Timeline
- 2026-07-14: advisory: GHSA-hgjx-r89m-m7v4 published
References
- https://api.github.com/users/aslein1413-sys
- https://github.com/aslein1413-sys
- https://api.github.com/users/aslein1413-sys/gists%7B/gist_id%7D
- https://api.github.com/users/aslein1413-sys/repos
- https://avatars.githubusercontent.com/u/247496863?v=4
- https://api.github.com/users/aslein1413-sys/events%7B/privacy%7D