CVE-2026-32699 Details
Description
FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser controller. Although the user interface prevents editing this field, a user can bypass this restriction by intercepting the request and modifying the nick form-data parameter to rename any account, including the administrator account. This leads to unauthorized modification of a field intended to be immutable.
A vulnerability in FacturaScripts accounting and invoicing software, in versions through 2025.92, allows users to bypass user interface restrictions and modify the 'nick' parameter during POST requests to the EditUser controller. This flaw arises because the application fails to validate changes to the 'nick' field, which is meant to be immutable. As a result, users can rename any account, including the administrator's, leading to unauthorized modifications and potential corruption of the audit log.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 5, 2026CISA-ADP
Assessed May 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-pp79-hqv6-vmc3 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/NeoRazorX/facturascripts/security/advisories/GHSA-pp79-hqv6-vmc3 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-472 | External Control of Assumed-Immutable Web Parameter | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NeoRazorX FacturaScripts | <= 2025.92 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | New CVE Received | [email protected] |
| May 5, 2026 | CVE Modified | CISA-ADP |
Volerion