Impact
The vulnerability exists in CubeCart v6 prior to release 6.7.5. The admin endpoints for resetting download counters (reset_id) and deleting stored payment cards (delete_card) are accessed through state‑changing GET requests that omit CSRF protection. An attacker who can coerce an authenticated administrator into sending one of these requests can cause unintended resets of digital download usage counters or removal of payment‑card tokens, disrupting future access to downloads and potentially impacting order processing. The flaw does not grant the attacker additional privileges beyond those already available to the admin, but it can lead to loss of revenue and customer trust due to unavailable content and disrupted payment methods.
Affected Systems
CubeCart v6, all releases before version 6.7.5. The issue is fixed starting with release 6.7.5.
Risk and Exploitability
The CVSS score is 5.3, reflecting moderate severity. The EPSS score is below 1%, indicating a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a user to be authenticated as an administrator and to be tricked into sending a GET request to either the reset_id download-counter or delete_card stored-payment-card action. Because these requests lack a validated CSRF token, the state change will succeed without further verification. The attacker’s ability to induce the action is therefore tied to social engineering or embedded content that forces the administrator to visit the malicious URL.
OpenCVE Enrichment