Description
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited value that changes the SET clause because HTML sanitization does not neutralize SQL syntax, allowing manipulation of database columns and potentially other data within the application's database privileges. This issue is fixed in version 6.7.5.
Published: 2026-09-17
Score: 7.2 High
EPSS: 1.4% Low
KEV: No
Impact: Database Compromise
Action: Patch
AI Analysis

Impact

The vulnerability is a classic SQL injection (CWE-89) in CubeCart's admin settings file. Prior to version 6.7.5, the POST parameter download_expire is concatenated directly into an UPDATE statement without numeric validation or parameterization. An authenticated administrator can supply a comma‑delimited value that rewrites the SET clause, allowing arbitrary database column updates and potentially other data changes within the application’s database scope.

Affected Systems

CubeCart e‑commerce software, version 6 for all releases before 6.7.5, including 6.7.4 and earlier. The flaw resides in admin/sources/settings.index.inc.php. Any deployment of CubeCart v6 that has not applied the 6.7.5 update is vulnerable.

Risk and Exploitability

The CVSS score is 7.2, indicating high severity, while the EPSS score of 1 % represents a modest likelihood of active exploitation. The flaw is not listed in the CISA KEV catalog. The exploitation requires the attacker to be authenticated as an administrator, so the attack vector is likely internal or over an exposed admin interface. Because the flaw permits arbitrary SQL manipulation under the database user’s privileges, an attacker can modify or delete data, extract information, or take broader control over the application’s database.

Generated by OpenCVE AI on September 19, 2026 at 19:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to CubeCart 6.7.5 or later, which sanitizes the download_expire parameter and removes the injection vector.
  • Until the update is applied, limit administrator access to the backend by IP filtering or firewall rules to minimize the chance of credential compromise.
  • Apply temporary code‑level mitigation by validating that the download_expire POST value consists solely of numeric characters before it is used in the UPDATE statement, or by replacing the raw string concatenation with a prepared statement.

Generated by OpenCVE AI on September 19, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cubecart
Cubecart v6
Vendors & Products Cubecart
Cubecart v6

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited value that changes the SET clause because HTML sanitization does not neutralize SQL syntax, allowing manipulation of database columns and potentially other data within the application's database privileges. This issue is fixed in version 6.7.5.
Title CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:23.503Z

Reserved: 2026-06-15T20:16:46.198Z

Link: CVE-2026-54647

cve-icon Vulnrichment

Updated: 2026-09-24T20:50:17.295Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:02.703

Modified: 2026-09-24T21:17:16.987

Link: CVE-2026-54647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')