Session Management Flaw in CubeCart E-commerce Software
CVE-2025-59335

7.1HIGH

Key Information:

Vendor

Cubecart

Status
Vendor
CVE Published:
22 September 2025

What is CVE-2025-59335?

CubeCart, a widely used e-commerce platform, has a significant security flaw that affects all versions before 6.5.11. This flaw concerns the lack of automatic session expiration when a user changes their password. If a user fails to log out from a device after changing their password, an unauthorized user could retain access to their account despite the password being updated. Consequently, if an account is compromised, users have no means to forcefully log out the attacker, leaving the account vulnerable until the session expires naturally. This issue has been addressed and resolved in version 6.5.11, emphasizing the importance of updating to the latest release for enhanced security.

Affected Version(s)

v6 < 6.5.11

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59335 : Session Management Flaw in CubeCart E-commerce Software