Impact
CubeCart modules allow an authenticated administrator to delete order history notes without checking the required delete permission for orders. When a request contains an order_id and delete-note parameter, the handler immediately removes the note record from CubeCart_order_notes, effectively erasing audit trail data. This flaw is an authorization bypass that can result in loss of historical transaction information and hampers accountability.
Affected Systems
The vulnerability affects CubeCart v6, specifically all releases prior to 6.7.5.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact. The EPSS score is less than 1%, suggesting a very low probability of exploitation at this time. The flaw is not listed in CISA’s KEV catalog. The likely attack route requires an authenticated administrator who lacks edit privileges for orders; from the public or internal network the attacker can invoke the vulnerable handler directly, but no remote code execution or privilege escalation is granted. Consequently, the risk to confidentiality or integrity is limited to the deletion of audit data, but it undermines system integrity and regulatory compliance.
OpenCVE Enrichment