Junglewise Threat Intelligence

CVE-2026-39358: CubeCart SQL injection in Products and Logs sorting parameters

CVE-2026-39358 · Severity: high · CVSS 7.2 · Published 2026-05-13

Technologies: CubeCart. Vendors: CubeCart.

Executive brief

CubeCart is an e-commerce platform used by businesses to manage online stores and customer transactions. A security flaw in the administrative interface allows an authorized user with high-level permissions to execute unauthorized database commands. This could lead to the theft of sensitive customer data, administrative credentials, or a complete shutdown of the online store.

Technical details

An authenticated time-based blind SQL injection vulnerability exists in CubeCart v6.x before version 6.6.0. The flaw is located in the sorting parameters (sort[price], sort_activity, sort_admin, and sort_customer) within the Products and Logs administrative endpoints. The application validates that the input is an array but fails to sanitize the values within that array before passing them to the database's select method. A remote attacker with high privileges (admin access) can inject SQL payloads, such as SLEEP() commands, to extract data byte-by-byte or cause a denial of service. The issue is addressed in version 6.6.0.

Affected products

  • CubeCart CubeCart v6.x Prior to 6.6.0

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-05-13: disclosed: NVD publication date

References

Related threats