Description
CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5.
Published: 2026-09-17
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

The CubeCart e‑commerce platform contains an unsanitized anchor tag injection flaw in its message rendering routine. The _errorMessage function uses strip_tags to allow anchor elements in error, information, and warning messages while leaving the href attribute and onclick event handler untouched. Attackers can embed a javascript: URI or add event handlers into a message that originates from user‑controlled input or search queries. When a victim views or clicks the rendered link, the JavaScript executes in the victim's browser session, providing a window for session hijacking or unauthorized actions within the application.

Affected Systems

All installations of CubeCart version 6 that use the GUI class file gui.class.php prior to the 6.7.5 release are affected. The issue was fixed in the 6.7.5 release, so version 6.7.5 and later are not vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 6.1, indicating moderate severity, and an EPSS score of 1%, suggesting a limited but non‑zero likelihood of exploitation in the near term. It is not currently listed in CISA’s KEV catalog. The injection can be performed by supplying malicious input that propagates to a GUI message, which an attacker can trigger by navigating to a specific page or by performing a search. Because the flaw is client‑side, it requires the victim to view or interact with the crafted link, but once executed the attacker can steal session data or perform unauthorized actions in the victim’s context.

Generated by OpenCVE AI on September 19, 2026 at 19:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official CubeCart 6.7.5 patch or upgrade to a later version.
  • If an upgrade is not immediately possible, modify the _errorMessage method to strip all href attributes and event‑handler attributes from anchor tags, or prevent anchor tags entirely from user‑controlled messages.
  • Limit user‑input that flows into GUI messages to only safe characters and validate inputs server‑side, ensuring that no JavaScript can be injected.

Generated by OpenCVE AI on September 19, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cubecart
Cubecart v6
Vendors & Products Cubecart
Cubecart v6
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning messages while retaining unsafe href values and onclick event handlers. Attacker-controlled search or input data that reaches a GUI message can carry a javascript: URI or event handler through the filter, and viewing or interacting with the rendered anchor executes JavaScript in the victim's browser session, enabling session exposure or unauthorized application actions. This issue is fixed in version 6.7.5.
Title CubeCart: XSS via Anchor Tag Attribute Injection in gui.class.php Message System
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:02:30.778Z

Reserved: 2026-06-15T20:16:46.198Z

Link: CVE-2026-54644

cve-icon Vulnrichment

Updated: 2026-09-18T20:02:23.394Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T22:17:02.283

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-54644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')