Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/cubecart/v6

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CubeCart v6 prior to version 6.7.5 contains a missing authorization vulnerability in the delete-note handler within the admin order management code. This flaw allows an authenticated administrator without order modification privileges to delete order-history notes by invoking the handler with valid parameters. The vulnerability permits removal of operational records and audit-trail data, potentially impacting order integrity and traceability. The issue is resolved in CubeCart version 6.7.5.

Join the discussion

CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-payment-card action in admin/sources/orders.index.inc.php use state-changing GET requests and are omitted from the protection map in admin/skins/default/csrf.inc.php. A remote attacker can induce an authenticated administrator to issue one of these requests without a validated session token, causing unintended resets of electronic download usage counters or deletion of stored customer payment-card tokens. This issue is fixed in version 6.7.5.

Join the discussion

CubeCart v6 prior to 6.7.5 contains a missing authorization vulnerability in its GDPR tools. Authenticated administrators with read-only customer privileges can bypass intended interface restrictions to delete customer records, accounts without orders, or guest accounts. This leads to irreversible deletion of data, impacting data integrity and availability. The issue is resolved in version 6.7.5.

Join the discussion

CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php … ?> into the Invoice Editor. The next time any admin clicks Print on any order, the rendered template is written to files/print.<md5>.php.files/.htaccess ships an explicit <Files print.*.php> allow from all </Files> carve-out, so the file is fetched and executed by any unauthenticated visitor. This vulnerability is fixed in 6.7.3.

Join the discussion

CubeCart versions 6.6.x through 6.7.1 have an improper input validation vulnerability where the software builds the CC_STORE_URL constant directly from the Host request header without validation. This value is used verbatim in transactional email links, including password reset links. An unauthenticated attacker can exploit this by sending a password recovery request with a malicious Host header, causing the victim to receive a password reset link pointing to an attacker-controlled domain. If the victim clicks the link, the attacker can gain full account takeover or store takeover if an admin account is targeted. This vulnerability is fixed in CubeCart version 6.7.

Join the discussion

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulnerability exists in multiple modules of CubeCart (including Email Templates, Invoices, Documents, and Contact Forms). The application unsafely evaluates user-supplied input using the Smarty template engine without enabling Smarty Security Policies. This allows any authenticated user with administrative privileges to execute arbitrary operating system commands (RCE) on the server. This vulnerability is fixed in 6.7.0.

Join the discussion

CubeCart v6 prior to version 6.7.0 contains an SQL injection vulnerability in the admin orders-transactions listing page. The vulnerability arises because the 'sort' parameter from the GET request is used directly in an ORDER BY SQL clause without proper validation or sanitization. This allows an authenticated administrator with read permissions on orders to execute arbitrary SQL commands against the database. The flaw is fixed in CubeCart version 6.7.0.

Join the discussion

CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart. The endpoint allows any holder of an API key with files:rw permission to upload PHP source files into the web-accessible images/source/ directory, where they are executed by the web server. Combined with a path-traversal flaw in the same endpoint's filepath parameter, a single API request writes a webshell anywhere the webserver process can write — including the document root — yielding full Remote Code Execution. This vulnerability is fixed in 6.7.0.

Join the discussion

CubeCart v6 ecommerce software versions prior to 6.7.0 contain a reflected cross-site scripting (XSS) vulnerability in the search feature. This occurs when a search returns exactly one product, causing user input to be reflected without proper sanitization due to a logic flaw. An unauthenticated attacker can exploit this to execute malicious JavaScript in a victim's browser. The vulnerability is fixed in version 6.7.0.

Join the discussion

CubeCart v6 prior to version 6.6.0 contains a stored Cross-Site Scripting (XSS) vulnerability that allows an attacker with administrative privileges to inject malicious JavaScript into product fields. These scripts are stored in the database and execute when users view the affected product pages, potentially leading to session hijacking or unauthorized actions. The vulnerability has a medium severity score of 4.8 and is fixed in CubeCart version 6.6.0.

Join the discussion

Showing 1 to 10 of 13 results

Filters:Package: pkg:github/cubecart/v6
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses