← Πίσω στην αναζήτηση CVE

CVE-2026-27892

FacturaScripts

Περιγραφή

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC metadata. Any authenticated user who downloaded an image could extract the uploader-s embedded metadata, which included GPS coordinates, device information, timestamps, embedded comments/notes, thumbnail previews, and other personally identifiable information (PII) preserved in the image metadata. Of all FacturaScripts- image upload features, only the Library module combined unrestricted uploads, persistent storage, authenticated download access, and a total lack of server-side metadata sanitization. This vulnerability carries significant real-world impact: an employee uploading a photo taken at their home inadvertently discloses their precise home address to every user with Library download access. This issue has been fixed in version 2026.

CVSS 6.5EPSS 0.22699999999999998%Κίνδυνος 0.66
Προβολή πηγής
Δημοσίευση
2026-05-18 22:16:38
Επηρεαζόμενες εκδόσεις
<2026
Τύπος
Core software
Τελευταία τροποποίηση
2026-07-24 13:10:00
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N