Description
CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the protection map in admin/skins/default/csrf.inc.php. A remote attacker can induce an authenticated administrator to issue one of these requests without a validated session token, causing unintended resets of electronic download usage counters or deletion of stored customer payment-card tokens. This issue is fixed in version 6.7.5.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized State Change via CSRF
Action: Patch Immediately
AI Analysis

Impact

The vulnerability exists in CubeCart v6 prior to release 6.7.5. The admin endpoints for resetting download counters (reset_id) and deleting stored payment cards (delete_card) are accessed through state‑changing GET requests that omit CSRF protection. An attacker who can coerce an authenticated administrator into sending one of these requests can cause unintended resets of digital download usage counters or removal of payment‑card tokens, disrupting future access to downloads and potentially impacting order processing. The flaw does not grant the attacker additional privileges beyond those already available to the admin, but it can lead to loss of revenue and customer trust due to unavailable content and disrupted payment methods.

Affected Systems

CubeCart v6, all releases before version 6.7.5. The issue is fixed starting with release 6.7.5.

Risk and Exploitability

The CVSS score is 5.3, reflecting moderate severity. The EPSS score is below 1%, indicating a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a user to be authenticated as an administrator and to be tricked into sending a GET request to either the reset_id download-counter or delete_card stored-payment-card action. Because these requests lack a validated CSRF token, the state change will succeed without further verification. The attacker’s ability to induce the action is therefore tied to social engineering or embedded content that forces the administrator to visit the malicious URL.

Generated by OpenCVE AI on September 19, 2026 at 01:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CubeCart to version 6.7.5 or later to apply the official CSRF fix.
  • If an upgrade is not immediately possible, modify the orders.index.inc.php module to reject the reset_id download-counter and delete_card actions when received via GET without a valid CSRF token.
  • Change the implementation to require POST for these state‑changing actions and enforce CSRF token validation on all administrative endpoints.

Generated by OpenCVE AI on September 19, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cubecart
Cubecart v6
Vendors & Products Cubecart
Cubecart v6

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the protection map in admin/skins/default/csrf.inc.php. A remote attacker can induce an authenticated administrator to issue one of these requests without a validated session token, causing unintended resets of electronic download usage counters or deletion of stored customer payment-card tokens. This issue is fixed in version 6.7.5.
Title CubeCart: CSRF Protection Missing for Download Resets and Card Deletions in orders.index.inc.php
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:23.627Z

Reserved: 2026-06-15T20:16:46.198Z

Link: CVE-2026-54642

cve-icon Vulnrichment

Updated: 2026-09-24T20:50:18.939Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:01.997

Modified: 2026-09-24T21:17:16.860

Link: CVE-2026-54642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)