PT-2026-40814 · Cubecart · Cubecart

CVE-2026-45708

·

Published

2026-05-13

·

Updated

2026-05-14

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CubeCart versions prior to 6.7.3
Description An administrator with documents edit permission can save raw PHP code into the Invoice Editor. When any administrator clicks Print on an order, the rendered template is written to files/print.<md5>.php. Due to an explicit carve-out in the files/.htaccess file that allows all access to print.*.php files, the file can be fetched and executed by any unauthenticated visitor.
Recommendations Update to version 6.7.3.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45708
GHSA-747J-4MMC-CJ63

Affected Products

Cubecart