Impact
The vulnerability is a classic SQL injection (CWE-89) in CubeCart's admin settings file. Prior to version 6.7.5, the POST parameter download_expire is concatenated directly into an UPDATE statement without numeric validation or parameterization. An authenticated administrator can supply a comma‑delimited value that rewrites the SET clause, allowing arbitrary database column updates and potentially other data changes within the application’s database scope.
Affected Systems
CubeCart e‑commerce software, version 6 for all releases before 6.7.5, including 6.7.4 and earlier. The flaw resides in admin/sources/settings.index.inc.php. Any deployment of CubeCart v6 that has not applied the 6.7.5 update is vulnerable.
Risk and Exploitability
The CVSS score is 7.2, indicating high severity, while the EPSS score of 1 % represents a modest likelihood of active exploitation. The flaw is not listed in the CISA KEV catalog. The exploitation requires the attacker to be authenticated as an administrator, so the attack vector is likely internal or over an exposed admin interface. Because the flaw permits arbitrary SQL manipulation under the database user’s privileges, an attacker can modify or delete data, extract information, or take broader control over the application’s database.
OpenCVE Enrichment