PT-2026-40814 · Cubecart · Cubecart

Published

2026-05-13

·

Updated

2026-05-14

·

CVE-2026-45708

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CubeCart versions prior to 6.7.3
Description An administrator with documents edit permission can save raw PHP code into the Invoice Editor. When any administrator clicks Print on an order, the rendered template is written to files/print.<md5>.php. Due to an explicit carve-out in the files/.htaccess file that allows all access to print.*.php files, the file can be fetched and executed by any unauthenticated visitor.
Recommendations Update to version 6.7.3.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-45708

Affected Products

Cubecart