PT-2026-95154 · Cubecart · Cubecart

·

CVE-2026-54646

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CubeCart versions prior to 6.7.5
Description An issue exists in the admin/sources/maintenance.index.inc.php endpoint where administrator-controlled tablename values are inserted into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without proper validation of identifiers or escaping of embedded backticks. An authenticated administrator can terminate the quoted identifier using a closing backtick to inject structural SQL, which may compromise the confidentiality, integrity, and availability of the database within the application's privileges.
Recommendations Update to version 6.7.5.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54646
GHSA-QCX6-CG43-FFMX

Affected Products

Cubecart