PT-2025-38742 · Cubecart · Cubecart

CVE-2025-59335

·

Published

2025-09-22

·

Updated

2025-09-22

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CubeCart versions prior to 6.5.11
Description CubeCart is an ecommerce software solution. Prior to version 6.5.11, user sessions do not automatically expire after a password change. This allows an attacker who has already compromised an account to maintain access even after the legitimate user changes their password, as the attacker’s session remains active until it naturally expires. This prevents the legitimate user from revoking the attacker’s access.
Recommendations Update to version 6.5.11 or later.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59335
GHSA-4VWH-X8M2-FMVV

Affected Products

Cubecart