{"id":"GHSA-3pgc-xqg9-cfr6","summary":"FacturaScripts Vulnerable to Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism","details":"### Summary\nA Critical vulnerability exists in the `Plugins::add()` function. The system fails to properly validate the file paths within uploaded ZIP archives. This allows an attacker to perform a Zip Slip attack, leading to Arbitrary File Write and Remote Code Execution (RCE) by overwriting sensitive .php files outside the designated plugins directory.\n\n### Details\nThe vulnerability is located in Plugins.php. While the `testZipFile` function attempts to validate that the ZIP contains only one root folder, it does not sanitize or validate the individual file paths within that folder.\n```js\n// Vulnerable logic in Plugins.php\nfor ($index = 0; $index \u003c $zipFile-\u003enumFiles; $index++) {\n    $data = $zipFile-\u003estatIndex($index);\n    $path = explode('/', $data['name']);\n    if (count($path) \u003e 1) {\n        $folders[$path[0]] = $path[0];\n    }\n} \n```\nAn attacker can bypass this check by naming a file `ValidPluginName/../../shell.php`. The explode function will see ValidPluginName as the root folder, satisfying the `count($folders) != 1` check. However, during extraction, the `../../` sequence triggers a path traversal, allowing the file to be written anywhere the web server has permissions the root directory.\n### PoC\nPrepare Malicious ZIP: Use a tool (like evilarc) or a script to create a ZIP file where one of the entries is named: `MyPlugin/../../rce.php`\nInject Payload: Inside rce.php, put a simple shell: \n`\u003c?php system($_GET['cmd']); ?\u003e`\nUpload: Navigate to the \"Add Plugin\" section in FacturaScripts and upload the malicious ZIP.\nExecution: Access the shell via https://target.com/rce.php?cmd=whoami.\n\n### Impact\nConfidentiality: High (Attacker can read all database configs and files).\nIntegrity: High (Attacker can modify any file on the server).\nAvailability: High (Attacker can delete the entire installation).\n\u003e https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-27891.md","aliases":["CVE-2026-27891"],"modified":"2026-05-07T19:56:27.875430Z","published":"2026-05-07T19:32:14Z","database_specific":{"github_reviewed_at":"2026-05-07T19:32:14Z","nvd_published_at":null,"cwe_ids":["CWE-20","CWE-434"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-3pgc-xqg9-cfr6"},{"type":"PACKAGE","url":"https://github.com/NeoRazorX/facturascripts"}],"affected":[{"package":{"name":"facturascripts/facturascripts","ecosystem":"Packagist","purl":"pkg:composer/facturascripts/facturascripts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2025.71"}]}],"versions":["2018.03","2018.04","2018.05","2018.11","v2018.12","v2018.13","v2018.14","v2018.15","v2018.16","v2020.01","v2020.2","v2020.3","v2020.4","v2020.51","v2020.61","v2020.71","v2020.80","v2021","v2021.1","v2021.2","v2021.4","v2021.51","v2021.71","v2021.81","v2022.06","v2022.08","v2022.2","v2022.4","v2022.51","v2023.03","v2023.08","v2023.16","v2023.21","v2024","v2024.1","v2024.2","v2024.3","v2024.5","v2024.7","v2024.8","v2024.9","v2024.91","v2024.93","v2024.94","v2024.95","v2024.96","v2025","v2025.11","v2025.2","v2025.3","v2025.4","v2025.41","v2025.43","v2025.7","v2025.71","v2025.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-3pgc-xqg9-cfr6/GHSA-3pgc-xqg9-cfr6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}