CubeCart 6.7.4 - SQL injection
CubeCart 6.7.4 - SQL injection
Indicators of Compromise
- exploit-code: # Exploit Title: CubeCart 6.7.4 - SQL injection # Date: 2026-06-08 # Exploit Author: Mikail Kocadağ # Vendor Homepage: https://www.cubecart.com/ # Software Link: https://github.com/cubecart/v6 # Vulnerable Version: 6.7.4 # Fixed Version: 6.7.5 # CVE: CVE-2026-54647 # Advisory / References: https://github.com/cubecart/v6/security/advisories/GHSA-hvmw-v8gc-4c29 -------------------------------------------------------------------------------- VULNERABILITY SUMMARY -------------------------------------------------------------------------------- An authenticated administrative SQL injection vulnerability exists in CubeCart v6.7.4 due to unsafe concatenation of user-supplied input in raw database queries without validation. The vulnerability is located in `admin/sources/settings.index.inc.php` at line 184. The `download_expire` parameter received via POST is directly concatenated into an `UPDATE` SQL statement executed via `query()` or `misc()`. The global input sanitizer (`Sanitize::_safety()`) relies entirely on `htmlspecialchars()`, which does not filter or encode commas (`,`). An attacker can leverage comma injection to break out of the intended syntax and manipulate the `SET` clauses or append malicious clauses. -------------------------------------------------------------------------------- IMPACT -------------------------------------------------------------------------------- An authenticated attacker with access to settings can manipulate arbitrary columns within the settings tables or potentially perform lateral movement within the database. -------------------------------------------------------------------------------- PROOF OF CONCEPT (PoC) -------------------------------------------------------------------------------- 1. Authenticated as an administrator, navigate to Settings. 2. Intercept the save request and inject a payload containing a comma into the `download_expire` field: 1, expire=0 WHERE 1=1-- - 3. Submit the request and verify that the raw SQL syntax is successfully altered.
CubeCart 6.7.4 - SQL injection
Description
CubeCart 6.7.4 - SQL injection
Technical Details
- Cve
- CVE-2026-54647
- Author
- Mikail Kocadağ
- Edb Id
- 52664
- Has Exploit Code
- true
- Code Language
- text
Indicators of Compromise
Exploit Source Code
Exploit code for CubeCart 6.7.4 - SQL injection
# Exploit Title: CubeCart 6.7.4 - SQL injection # Date: 2026-06-08 # Exploit Author: Mikail Kocadağ # Vendor Homepage: https://www.cubecart.com/ # Software Link: https://github.com/cubecart/v6 # Vulnerable Version: 6.7.4 # Fixed Version: 6.7.5 # CVE: CVE-2026-54647 # Advisory / References: https://github.com/cubecart/v6/security/advisories/GHSA-hvmw-v8gc-4c29 -------------------------------------------------------------------------------- VULNERABILITY SUMMARY ----------------------------------... (1536 more characters)
Threat ID: 6a95bd28acd9273b49648ee3
Added to database: 08/31/2026, 17:43:04 UTC
Last updated: 08/31/2026, 20:12:19 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.