Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25513

Опубликовано: 04 фев. 2026
Источник: nvd
EPSS Низкий

Описание

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScripts contains a critical SQL injection vulnerability in the REST API that allows authenticated API users to execute arbitrary SQL queries through the sort parameter. The vulnerability exists in the ModelClass::getOrderBy() method where user-supplied sorting parameters are directly concatenated into the SQL ORDER BY clause without validation or sanitization. This affects all API endpoints that support sorting functionality. This issue has been patched in version 2025.81.

EPSS

Процентиль: 19%
0.0006
Низкий

Дефекты

CWE-20

Связанные уязвимости

github
3 дня назад

FacturaScripts has SQL Injection in API ORDER BY Clause

EPSS

Процентиль: 19%
0.0006
Низкий

Дефекты

CWE-20