CSRF Vulnerability in CubeCart eCommerce Software by CubeCart
CVE-2026-54642

5.3MEDIUM

Key Information:

Vendor

Cubecart

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54642?

A CSRF vulnerability exists in CubeCart's ecommerce solution impacting versions prior to 6.7.5. The issue arises from the reset_id download-counter and delete_card stored-payment-card actions being susceptible to state-changing GET requests, which bypass protections implemented in the platform. An attacker might exploit this flaw to manipulate an authenticated administrator into executing harmful actions without proper session validation, leading to unauthorized resets of download usage counters or potential deletion of sensitive payment card tokens. Users are advised to upgrade to version 6.7.5 to mitigate these risks.

Affected Version(s)

v6 < 6.7.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.