Cross-Site Scripting Risk in CubeCart E-Commerce Software
CVE-2025-59411
5.4MEDIUM
What is CVE-2025-59411?
CubeCart, an ecommerce solution, contains a vulnerability where the contact form’s Enquiry field permits the submission of unfiltered HTML. This HTML is subsequently sent to the store administrator in email notifications, without any escaping or sanitization. As a result, this flaw opens the door to Cross-Site Scripting (XSS) attacks within email clients or administrative interfaces. This issue is resolved in version 6.5.11, which addresses the improper handling of user input.
Affected Version(s)
v6 < 6.5.11