Impact
The CubeCart e‑commerce platform contains an unsanitized anchor tag injection flaw in its message rendering routine. The _errorMessage function uses strip_tags to allow anchor elements in error, information, and warning messages while leaving the href attribute and onclick event handler untouched. Attackers can embed a javascript: URI or add event handlers into a message that originates from user‑controlled input or search queries. When a victim views or clicks the rendered link, the JavaScript executes in the victim's browser session, providing a window for session hijacking or unauthorized actions within the application.
Affected Systems
All installations of CubeCart version 6 that use the GUI class file gui.class.php prior to the 6.7.5 release are affected. The issue was fixed in the 6.7.5 release, so version 6.7.5 and later are not vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 6.1, indicating moderate severity, and an EPSS score of 1%, suggesting a limited but non‑zero likelihood of exploitation in the near term. It is not currently listed in CISA’s KEV catalog. The injection can be performed by supplying malicious input that propagates to a GUI message, which an attacker can trigger by navigating to a specific page or by performing a search. Because the flaw is client‑side, it requires the victim to view or interact with the crafted link, but once executed the attacker can steal session data or perform unauthorized actions in the victim’s context.
OpenCVE Enrichment