PT-2026-95155 · Cubecart · Cubecart

·

CVE-2026-54647

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CubeCart versions prior to 6.7.5
Description An issue exists in the ecommerce software where the endpoint 'admin/sources/settings.index.inc.php' directly concatenates the download expire POST parameter into a raw UPDATE statement for CubeCart downloads without numeric validation. An authenticated administrator can provide a comma-delimited value to alter the SET clause, as HTML sanitization does not neutralize SQL syntax. This allows for the manipulation of database columns and other data accessible within the application's database privileges through SQL Injection, a technique where malicious SQL statements are inserted into entry fields for execution.
Recommendations Update to version 6.7.5.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54647
GHSA-HVMW-V8GC-4C29

Affected Products

Cubecart