Session Management Flaw in CubeCart E-commerce Software
CVE-2025-59335
7.1HIGH
What is CVE-2025-59335?
CubeCart, a widely used e-commerce platform, has a significant security flaw that affects all versions before 6.5.11. This flaw concerns the lack of automatic session expiration when a user changes their password. If a user fails to log out from a device after changing their password, an unauthorized user could retain access to their account despite the password being updated. Consequently, if an account is compromised, users have no means to forcefully log out the attacker, leaving the account vulnerable until the session expires naturally. This issue has been addressed and resolved in version 6.5.11, emphasizing the importance of updating to the latest release for enhanced security.
Affected Version(s)
v6 < 6.5.11