
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23997 is a Stored Cross-Site Scripting (XSS) vulnerability in FacturaScripts, an open-source accounting and ERP application, affecting all versions up to and including 2025.71. The flaw exists in the "Observations" field of Delivery Notes, where historical data is rendered in the History view without proper HTML entity encoding, allowing injected JavaScript to execute in an administrator's browser session. Discovered and disclosed on February 2, 2026, the vulnerability was reported by researcher jaroslaw-wawiorko and published by NeoRazorX. The CVSS v3.1 base score is 8.0 (High) per the GitHub Advisory, though Feedly's aggregated data notes a score of 9.0 (Critical) with a changed scope (GitHub Advisory, NeoRazorX Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting): the History view renders stored Observations field content without HTML entity encoding, allowing arbitrary JavaScript injection. An attacker with note-editing permissions (a low-privileged authenticated user) injects a malicious script into the Observations field of a Delivery Note; when an administrator later views the History tab for that record, the stored payload executes in the admin's browser session. The attack further exploits the absence of a "current password" verification requirement and bypasses CSRF protections during the password change API call, enabling full credential takeover via the injected script. The internal API structure needed to craft the password-change payload can be discovered by any legitimate user through browser developer tools, and the default admin username is commonly known (GitHub Advisory, NeoRazorX Advisory).
Successful exploitation results in a critical full account takeover of the FacturaScripts admin account, granting the attacker complete control over system management functions, sensitive financial data, and user configurations. Because the attack changes the admin password without requiring the current password and bypasses CSRF protections, the legitimate administrator is effectively locked out. The attacker gains access to all data managed by the ERP/accounting platform, including customer records, financial transactions, and system settings (GitHub Advisory, NeoRazorX Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, detailing the exact steps to inject the payload and trigger admin password change via XSS (NeoRazorX Advisory). As of the time of disclosure, there is no confirmed evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014% (0.000140), indicating a currently low probability of active exploitation within 30 days (GitHub Advisory). No threat actor attribution has been reported.
fetch() or XMLHttpRequest to call the password change endpoint with the new credentials, bypassing CSRF token requirements.<img src=x onerror="fetch('/api/change-password', {method:'POST', body:...})">) in the Observations field and save.onerror event (or equivalent) triggers, executing the JavaScript in the admin's authenticated browser session.<img, <script, onerror=) in the Observations field of Delivery Notes in the database (GitHub Advisory).The GitHub Advisory lists affected versions as ≤ 2025.71 with no patched version explicitly named at the time of publication; however, Feedly's patch details indicate that upgrading to version 2025.71 or later (the next release after the vulnerable range) is the recommended remediation (GitHub Advisory). As an immediate workaround, restrict note-editing permissions to only highly trusted users, and monitor admin account activity for unauthorized password changes. Additionally, review recent admin password change events and audit the Observations fields of existing Delivery Notes for suspicious JavaScript content. Implement proper HTML entity encoding in the History view as a code-level fix if a patched release is not yet available.
The vulnerability was shared on Bluesky by TheHackerWire shortly after disclosure, and was picked up by several vulnerability tracking platforms including Vulners, CVEFeed, and VulDB (GitHub Advisory). No significant vendor statements beyond the original advisory or notable independent researcher commentary have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."