PT-2025-38742 · Cubecart · Cubecart

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-59335

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CubeCart versions prior to 6.5.11
Description CubeCart is an ecommerce software solution. Prior to version 6.5.11, user sessions do not automatically expire after a password change. This allows an attacker who has already compromised an account to maintain access even after the legitimate user changes their password, as the attacker’s session remains active until it naturally expires. This prevents the legitimate user from revoking the attacker’s access.
Recommendations Update to version 6.5.11 or later.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2025-59335
GHSA-4VWH-X8M2-FMVV

Affected Products

Cubecart