{"id":"GHSA-gq5c-rw37-g46c","summary":"FacturaScripts vulnerable to Reflected Cross-Site Scripting (XSS) via Cookie Manipulation","details":"### Summary\nA Reflected Cross-Site Scripting (XSS) vulnerability exists in the fsNick cookie parameter. The application reflects the cookie's value directly into the HTML without sanitization.\n\n### Details\nThe fsNick cookie is rendered into the DOM without encoding. While the server does reject the modified session and forces a logout, the HTML containing the payload reaches the browser first. This lets the script execute immediately upon load, effectively beating the redirect.\n\n### PoC\n\n1. Log in to the application with any valid account.\n\u003cimg width=\"2078\" height=\"302\" alt=\"image\" src=\"https://github.com/user-attachments/assets/d8a9a779-44e0-4a3e-839f-0a031868fbd5\" /\u003e\n\n2. Capture any the GET request .\n\u003cimg width=\"1267\" height=\"276\" alt=\"image\" src=\"https://github.com/user-attachments/assets/22e43f73-4f86-4cab-a074-7aba584a71ac\" /\u003e\n\n3. Modify  the value of \"fsNick\" with the following JavaScript:\n`\u003cscript\u003ealert(window.origin)\u003c/script\u003e`\n\n4. Send the modified request.\n\u003cimg width=\"1569\" height=\"319\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ade88db1-aadc-4c50-9e02-d09888067e98\" /\u003e\n\n5. Result\n\u003cimg width=\"1217\" height=\"771\" alt=\"image\" src=\"https://github.com/user-attachments/assets/5858fe9f-127a-4845-b484-5a7ef4ae2cb4\" /\u003e\n\n### Impact\nThe payload executes before the session ends, which could potentially allow for a single unauthorized action before the logout.","aliases":["CVE-2026-27964"],"modified":"2026-09-10T03:51:05.828908141Z","published":"2026-05-07T19:34:28Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-05-07T19:34:28Z","nvd_published_at":"2026-05-18T22:16:38Z","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-gq5c-rw37-g46c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27964"},{"type":"WEB","url":"https://github.com/NeoRazorX/facturascripts/commit/9066e10326029adf012114e27eb5f3f33f78ecfd"},{"type":"PACKAGE","url":"https://github.com/NeoRazorX/facturascripts"}],"affected":[{"package":{"name":"facturascripts/facturascripts","ecosystem":"Packagist","purl":"pkg:composer/facturascripts/facturascripts"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2025.71"}]}],"versions":["2018.03","2018.04","2018.05","2018.11","v2018.12","v2018.13","v2018.14","v2018.15","v2018.16","v2020.01","v2020.2","v2020.3","v2020.4","v2020.51","v2020.61","v2020.71","v2020.80","v2021","v2021.1","v2021.2","v2021.4","v2021.51","v2021.71","v2021.81","v2022.06","v2022.08","v2022.2","v2022.4","v2022.51","v2023.03","v2023.08","v2023.16","v2023.21","v2024","v2024.1","v2024.2","v2024.3","v2024.5","v2024.7","v2024.8","v2024.9","v2024.91","v2024.93","v2024.94","v2024.95","v2024.96","v2025","v2025.11","v2025.2","v2025.3","v2025.4","v2025.41","v2025.43","v2025.7","v2025.71","v2025.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-gq5c-rw37-g46c/GHSA-gq5c-rw37-g46c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"}]}