Vulnerability in CubeCart E-commerce Software Exposes User Accounts
CVE-2026-45055
8.1HIGH
What is CVE-2026-45055?
The CubeCart e-commerce platform, up to version 6.7.1, allows unauthenticated attackers to take over user accounts by exploiting improper input validation in the password reset feature. By manipulating the Host request header, an attacker can craft a request that triggers the system to send a verification link containing a valid token to the target user's email. This token can be used to gain full access to the victim's account or, if the target is an admin, potentially lead to complete administrative control over the store. The vulnerability has been addressed in version 6.7.2, which includes necessary safety measures to prevent such exploits.
Affected Version(s)
v6 < 6.7.2
