PT-2026-95156 · Cubecart · Cubecart
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CubeCart versions prior to 6.7.5
Description
An authorization bypass exists in the GDPR tools located in the
admin/sources/customers.gdpr.inc.php file. The system relies on page-level CC PERM READ access and fails to require CC PERM DELETE for the purge, no order purge, and delete guests commands. Consequently, an authenticated administrator with only read-only customer privileges can directly invoke these backend actions to bypass interface restrictions and irreversibly delete customer records, accounts without orders, or guest accounts, which compromises data integrity and availability.Recommendations
Update to version 6.7.5.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cubecart