PT-2025-38745 · Cubecart · Cubecart
Published
2025-09-22
·
Updated
2025-09-22
·
CVE-2025-59413
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
CubeCart versions prior to 6.5.11
Description
A flaw exists in the newsletter subscription functionality that permits unauthorized user unsubscription. An attacker can manipulate the
force unsubscribe parameter in a POST request to the newsletter subscription endpoint to remove any valid subscriber’s email address without their consent. The affected endpoint is the newsletter subscription endpoint. The vulnerable parameter is force unsubscribe.Recommendations
Update to version 6.5.11 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cubecart