Impact
CubeCart versions prior to 6.7.5 allow an authenticated administrator who only has read‑only customer privileges to call backend GDPR functions that will irrevocably delete customer records, accounts without orders, or guest accounts. The vulnerability arises because the file admins/sources/customers.gdpr.inc.php does not enforce the required CC_PERM_DELETE authorization check for the purge, no_order_purge and delete_guests commands, resulting in a loss of data integrity and availability.
Affected Systems
The affected product is CubeCart v6, with all releases prior to 6.7.5 lacking the authorization guard. Version 6.7.5 and later include the fix, so customers on 6.7.4 or earlier are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires an authenticated administrator; the attacker does not need elevated deletion rights because the backend actions bypass the interface’s permission checks. If an attacker gains read‑only customer access, they can trigger the deletion endpoints to destroy customer data.
OpenCVE Enrichment