CubeCart 6.7.4 - Stored XSS
CubeCart 6.7.4 - Stored XSS
Indicators of Compromise
- exploit-code: # Exploit Title: CubeCart 6.7.4 - Stored Cross-Site Scripting # Date: 2026-06-08 # Exploit Author: Mikail Kocadağ (MKLKCDG) # Vendor Homepage: https://www.cubecart.com/ # Software Link: https://github.com/cubecart/v6 # Vulnerable Version: 6.7.4 # Fixed Version: 6.7.5 # CVE: CVE-2026-54645 # Advisory / References: https://github.com/cubecart/v6/security/advisories/GHSA-43f6-gfcf-wj9c -------------------------------------------------------------------------------- VULNERABILITY SUMMARY -------------------------------------------------------------------------------- A Stored Cross-Site Scripting (XSS) vulnerability exists in the product management panel of CubeCart 6.7.4, where product descriptions bypass global input filters and sanitization controls. In `admin/sources/products.index.inc.php` (lines 55-59), the application explicitly bypasses the global sanitizer mechanism by retrieving content directly from `$GLOBALS['RAW']['POST']`. The only defense applied is a basic regex filter against `<script>` tags, which fails to block alternative XSS vectors like event handlers or SVG elements. -------------------------------------------------------------------------------- IMPACT -------------------------------------------------------------------------------- An attacker with product editing permissions can inject persistent malicious JavaScript. When clients or other administrators view the affected product page on either the public storefront or the administration panel, the payload executes within their active session. -------------------------------------------------------------------------------- PROOF OF CONCEPT (PoC) -------------------------------------------------------------------------------- 1. Log into the administration panel and navigate to Product Management. 2. Edit or create a product, and inject a payload using an HTML event handler into the product description: <img src=x onerror=alert(document.domain)> 3. Save the product. 4. Visit the product page on the public storefront or view it within the admin panel to trigger execution.
CubeCart 6.7.4 - Stored XSS
Description
CubeCart 6.7.4 - Stored XSS
Technical Details
- Cve
- CVE-2026-54645
- Author
- Mikail Kocadağ
- Edb Id
- 52662
- Has Exploit Code
- true
- Code Language
- text
Indicators of Compromise
Exploit Source Code
Exploit code for CubeCart 6.7.4 - Stored XSS
# Exploit Title: CubeCart 6.7.4 - Stored Cross-Site Scripting # Date: 2026-06-08 # Exploit Author: Mikail Kocadağ (MKLKCDG) # Vendor Homepage: https://www.cubecart.com/ # Software Link: https://github.com/cubecart/v6 # Vulnerable Version: 6.7.4 # Fixed Version: 6.7.5 # CVE: CVE-2026-54645 # Advisory / References: https://github.com/cubecart/v6/security/advisories/GHSA-43f6-gfcf-wj9c -------------------------------------------------------------------------------- VULNERABILITY SUMMARY ---------... (1586 more characters)
Threat ID: 6a95bd28acd9273b49648ee9
Added to database: 08/31/2026, 17:43:04 UTC
Last updated: 08/31/2026, 21:08:03 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.