CVE-2026-25514: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-25514 is a SQL injection vulnerability in the autocomplete functionality of FacturaScripts, an open-source ERP and accounting software. The flaw exists in the CodeModel::all() method, where user-supplied parameters are directly concatenated into SQL queries without sanitization or parameterized binding, allowing any authenticated user to extract sensitive data from the database. It affects all FacturaScripts versions prior to 2025.81 and was disclosed on February 3, 2026, by researcher Łukasz Rybak via a GitHub Security Advisory. The vulnerability carries a CVSS v3.1 score of 8.8 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, NeoRazorX Advisory).

Technical details

The root cause is improper input validation (CWE-20) and SQL injection (CWE-89, CWE-943) in /Core/Model/CodeModel.php. The all() method constructs SQL queries by directly concatenating the $tableName, $fieldCode, and $fieldDescription parameters — sourced from user-controlled POST parameters source, fieldcode, and fieldtitle respectively — without any escaping or allowlisting. Multiple controllers including CopyModel, ListController, and PanelController expose this vulnerable code path via their autocomplete action. An attacker sends a crafted POST request to /CopyModel?action=autocomplete with a malicious SQL expression (e.g., version() or concat(user(),' @ ',database())) in the fieldtitle parameter, and the application returns the query result in JSON format. A CSRF token (multireqtoken) is required per request but is trivially obtainable from any authenticated page load (GitHub Advisory, Patch Commit).

Impact

Successful exploitation enables complete database disclosure, exposing user credentials (password hashes), customer personally identifiable information (names, addresses, tax IDs), financial records (invoices, payments, bank details), business configuration data, and plugin settings. Any authenticated user — not just administrators — can exploit this vulnerability, significantly broadening the attack surface. The integrity and availability of the system are also rated High, meaning an attacker could potentially modify or destroy database content in addition to exfiltrating it (GitHub Advisory).

Exploitability

A detailed proof-of-concept (PoC) exploit — including both manual curl-based steps and a full Python automation script — was published as part of the GitHub Security Advisory at the time of disclosure on February 3, 2026. The exploit has also been indexed by Sploitus. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.029% (9th percentile), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing FacturaScripts installations running versions prior to 2025.81 using web search or application fingerprinting.
  2. Obtain session cookie and CSRF token: Send a GET request to the /login page and extract the multireqtoken value from the HTML response:
    TOKEN=$(curl -s -L -c cookies.txt "http://TARGET/login" | grep -Po 'name="multireqtoken" value="\K[^"]+') 
  3. Authenticate: Submit valid credentials (any user role) along with the CSRF token to establish an authenticated session:
    curl -s -b cookies.txt -c cookies.txt -X POST "http://TARGET/login" \
      -d "fsNick=user" -d "fsPassword=pass" -d "action=login" -d "multireqtoken=$TOKEN"
  4. Obtain a fresh CSRF token: Retrieve a new multireqtoken from the /CopyModel page before each injection request.
  5. Inject SQL payload via fieldtitle parameter: Send a POST request to /CopyModel with action=autocomplete and a malicious SQL expression in fieldtitle:
    curl -s -b cookies.txt "http://TARGET/CopyModel" \
      -d "action=autocomplete" -d "source=users" -d "fieldcode=nick" \
      -d "fieldtitle=password" -d "term=admin" -d "multireqtoken=$TOKEN"
  6. Extract sensitive data: Parse the JSON response to retrieve the injected data (e.g., admin password hash). Use payloads such as concat(user(),' @ ',database()) or (SELECT GROUP_CONCAT(table_name) FROM information_schema.tables WHERE table_schema=database()) to enumerate the database.
  7. Automate extraction: Use the published Python PoC script to systematically extract all tables, credentials, and business data (GitHub Advisory).

Indicators of compromise

  • Network: Unusual POST requests to /CopyModel, /ListController, or /PanelController endpoints with action=autocomplete and fieldtitle values containing SQL functions (e.g., version(), concat(, GROUP_CONCAT, information_schema).
  • Logs: FacturaScripts application logs showing entries for invalid-autocomplete-source or invalid-field-name / invalid-field-description (generated by the patched version when blocking injection attempts); web server access logs with repeated autocomplete POST requests from a single authenticated session.
  • Logs: Responses returning unexpected JSON data structures containing database metadata, version strings, or concatenated field values inconsistent with normal autocomplete usage.
  • File System: Presence of exploit scripts (e.g., Python files referencing CodeModel, autocomplete, fieldtitle) on attacker-controlled systems or uploaded to the server.
  • Process/DB: Unexpected queries in database slow query logs or general query logs referencing information_schema.tables, version(), or concat(user() originating from the FacturaScripts application user (GitHub Advisory).

Mitigation and workarounds

Upgrade FacturaScripts to version 2025.81 or later, which contains the fix. The patch (commit 5c070f8) addresses the vulnerability in two ways: (1) CodeModel.php now validates fieldCode and fieldDescription parameters against a strict allowlist regex (/^[a-zA-Z0-9_.]+$/) via the new isValidFieldName() method; and (2) CopyModel.php restricts the source parameter to an explicit allowlist (Cliente, Contacto, Proveedor, and their table equivalents). No configuration-based workaround is available for unpatched versions; upgrading is the only remediation (Patch Commit, GitHub Advisory).

Community reactions

The vulnerability was discovered and responsibly disclosed by researcher Łukasz Rybak, who published a detailed advisory including a full PoC exploit script. The advisory was reviewed and published by NeoRazorX (the maintainer) on February 3, 2026, and patched the same day. The vulnerability was subsequently indexed by Sploitus and covered in the Secret CISO newsletter. No major vendor statements beyond the official advisory or significant social media controversy have been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management