Description
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product content and enabling session exposure or unauthorized browser-context actions. This issue is fixed in version 6.7.5.
Published: 2026-09-17
Score: 4.8 Medium
EPSS: 1.1% Low
KEV: No
Impact: Stored Cross‑Site Scripting affecting both administrators and storefront visitors
Action: Apply Patch
AI Analysis

Impact

CubeCart versions prior to 6.7.5 allow administrators with product‑editing rights to store malicious content in the product description fields. The global sanitizer removes only <script> elements, but it fails to strip event‑handler attributes, SVG content, or javascript: URIs, enabling persistent JavaScript execution when the product page is viewed. This can lead to session exposure, unofficial actions performed in the victim’s browser context, and other cross‑site scripting impacts.

Affected Systems

The vulnerability affects CubeCart v6 implementations that have not applied the 6.7.5 update. All deployments using the product‑description editing feature without this patch are at risk; administrators and storefront users of these versions could be impacted.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, while an EPSS score of 1% reflects a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack exploitation requires an administrator to input malicious content, but the resulting stored XSS can be accessed by any storefront visitor, expanding the potential threat surface. In practice, an attacker gaining product‑editing access or controlling the product description input can hijack sessions or perform unauthorized actions in the users’ browsers.

Generated by OpenCVE AI on September 19, 2026 at 19:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CubeCart to version 6.7.5 or newer, which provides the necessary input sanitization fix
  • Restrict product‑editing permissions to trusted administrators only, reducing the attack surface for malicious input
  • Add server‑side validation to remove event‑handler attributes, javascript: URIs, and SVG elements from product description fields if patching is delayed

Generated by OpenCVE AI on September 19, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cubecart
Cubecart v6
Vendors & Products Cubecart
Cubecart v6

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements before the values are stored and rendered through Smarty templates. An administrator with product-editing rights can store event-handler attributes, SVG content, or javascript: URIs that bypass this filter, causing persistent JavaScript execution when a storefront visitor or another administrator views the product content and enabling session exposure or unauthorized browser-context actions. This issue is fixed in version 6.7.5.
Title CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T01:58:02.824Z

Reserved: 2026-06-15T20:16:46.198Z

Link: CVE-2026-54645

cve-icon Vulnrichment

Updated: 2026-09-22T01:57:55.800Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:02.420

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')