Impact
CubeCart versions prior to 6.7.5 allow administrators with product‑editing rights to store malicious content in the product description fields. The global sanitizer removes only <script> elements, but it fails to strip event‑handler attributes, SVG content, or javascript: URIs, enabling persistent JavaScript execution when the product page is viewed. This can lead to session exposure, unofficial actions performed in the victim’s browser context, and other cross‑site scripting impacts.
Affected Systems
The vulnerability affects CubeCart v6 implementations that have not applied the 6.7.5 update. All deployments using the product‑description editing feature without this patch are at risk; administrators and storefront users of these versions could be impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while an EPSS score of 1% reflects a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack exploitation requires an administrator to input malicious content, but the resulting stored XSS can be accessed by any storefront visitor, expanding the potential threat surface. In practice, an attacker gaining product‑editing access or controlling the product description input can hijack sessions or perform unauthorized actions in the users’ browsers.
OpenCVE Enrichment