
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25514 is a SQL injection vulnerability in the autocomplete functionality of FacturaScripts, an open-source ERP and accounting software. The flaw exists in the CodeModel::all() method, where user-supplied parameters are directly concatenated into SQL queries without sanitization or parameterized binding, allowing any authenticated user to extract sensitive data from the database. It affects all FacturaScripts versions prior to 2025.81 and was disclosed on February 3, 2026, by researcher Łukasz Rybak via a GitHub Security Advisory. The vulnerability carries a CVSS v3.1 score of 8.8 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, NeoRazorX Advisory).
The root cause is improper input validation (CWE-20) and SQL injection (CWE-89, CWE-943) in /Core/Model/CodeModel.php. The all() method constructs SQL queries by directly concatenating the $tableName, $fieldCode, and $fieldDescription parameters — sourced from user-controlled POST parameters source, fieldcode, and fieldtitle respectively — without any escaping or allowlisting. Multiple controllers including CopyModel, ListController, and PanelController expose this vulnerable code path via their autocomplete action. An attacker sends a crafted POST request to /CopyModel?action=autocomplete with a malicious SQL expression (e.g., version() or concat(user(),' @ ',database())) in the fieldtitle parameter, and the application returns the query result in JSON format. A CSRF token (multireqtoken) is required per request but is trivially obtainable from any authenticated page load (GitHub Advisory, Patch Commit).
Successful exploitation enables complete database disclosure, exposing user credentials (password hashes), customer personally identifiable information (names, addresses, tax IDs), financial records (invoices, payments, bank details), business configuration data, and plugin settings. Any authenticated user — not just administrators — can exploit this vulnerability, significantly broadening the attack surface. The integrity and availability of the system are also rated High, meaning an attacker could potentially modify or destroy database content in addition to exfiltrating it (GitHub Advisory).
A detailed proof-of-concept (PoC) exploit — including both manual curl-based steps and a full Python automation script — was published as part of the GitHub Security Advisory at the time of disclosure on February 3, 2026. The exploit has also been indexed by Sploitus. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.029% (9th percentile), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
/login page and extract the multireqtoken value from the HTML response:TOKEN=$(curl -s -L -c cookies.txt "http://TARGET/login" | grep -Po 'name="multireqtoken" value="\K[^"]+') curl -s -b cookies.txt -c cookies.txt -X POST "http://TARGET/login" \
-d "fsNick=user" -d "fsPassword=pass" -d "action=login" -d "multireqtoken=$TOKEN"multireqtoken from the /CopyModel page before each injection request.fieldtitle parameter: Send a POST request to /CopyModel with action=autocomplete and a malicious SQL expression in fieldtitle:curl -s -b cookies.txt "http://TARGET/CopyModel" \
-d "action=autocomplete" -d "source=users" -d "fieldcode=nick" \
-d "fieldtitle=password" -d "term=admin" -d "multireqtoken=$TOKEN"concat(user(),' @ ',database()) or (SELECT GROUP_CONCAT(table_name) FROM information_schema.tables WHERE table_schema=database()) to enumerate the database./CopyModel, /ListController, or /PanelController endpoints with action=autocomplete and fieldtitle values containing SQL functions (e.g., version(), concat(, GROUP_CONCAT, information_schema).invalid-autocomplete-source or invalid-field-name / invalid-field-description (generated by the patched version when blocking injection attempts); web server access logs with repeated autocomplete POST requests from a single authenticated session.CodeModel, autocomplete, fieldtitle) on attacker-controlled systems or uploaded to the server.information_schema.tables, version(), or concat(user() originating from the FacturaScripts application user (GitHub Advisory).Upgrade FacturaScripts to version 2025.81 or later, which contains the fix. The patch (commit 5c070f8) addresses the vulnerability in two ways: (1) CodeModel.php now validates fieldCode and fieldDescription parameters against a strict allowlist regex (/^[a-zA-Z0-9_.]+$/) via the new isValidFieldName() method; and (2) CopyModel.php restricts the source parameter to an explicit allowlist (Cliente, Contacto, Proveedor, and their table equivalents). No configuration-based workaround is available for unpatched versions; upgrading is the only remediation (Patch Commit, GitHub Advisory).
The vulnerability was discovered and responsibly disclosed by researcher Łukasz Rybak, who published a detailed advisory including a full PoC exploit script. The advisory was reviewed and published by NeoRazorX (the maintainer) on February 3, 2026, and patched the same day. The vulnerability was subsequently indexed by Sploitus and covered in the Secret CISO newsletter. No major vendor statements beyond the official advisory or significant social media controversy have been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."