Impact
An authenticated administrator of CubeCart can inject arbitrary structural SQL by terminating a table name with a backtick in maintenance.index.inc.php. The code then treats the injected portion as part of the statement, enabling modifications to database structure or the execution of additional queries. This is a classic SQL identifier injection (CWE-89) that threatens the confidentiality, integrity, and availability of the application’s database.
Affected Systems
CubeCart version 6, all releases before 6.7.5. Those versions embed administrator‑controlled table names into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE commands without validating or escaping backticks, creating an identifiable vulnerability.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate to high severity, while the EPSS of 1% suggests a low overall exploitation probability; the weakness requires authenticated administrator privileges, limiting the attack surface. The vulnerability is not listed in the CISA KEV catalog. The attack vector likely involves an attacker who gains admin credentials or exploits a session hijack to deliver the backtick-bypass payload, which can result in database tampering, data loss, or service interruption.
OpenCVE Enrichment