PT-2026-40803 · Cubecart · Cubecart
Published
2026-05-13
·
Updated
2026-05-13
·
CVE-2026-39358
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CubeCart versions prior to 6.6.0
Description
Authenticated Time-Based Blind SQL Injection—a technique that allows an attacker to infer data by observing the time the server takes to respond to specific queries—exists in the Products and Logs endpoints. The issue resides in the sorting parameters
sort[price], sort activity, sort admin, and sort customer, enabling an attacker to execute arbitrary SQL commands and compromise the confidentiality and integrity of the database.Recommendations
Update to version 6.6.0.
As a temporary workaround, restrict access to the sorting parameters
sort[price], sort activity, sort admin, and sort customer in the Products and Logs endpoints.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cubecart