Executive brief
CubeCart is an e-commerce platform used by businesses to manage online stores. A security flaw in its search feature allows attackers to execute malicious code in the browsers of other users, including store administrators. This could lead to the theft of login sessions, unauthorized access to customer data, or the defacement of the online store. The attack is triggered when a victim clicks a specially crafted link that performs a search returning exactly one product.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in CubeCart v6.x within the `classes/catalogue.class.php` file. The vulnerability is caused by a logic flaw where the `search[keywords]` parameter is passed to `setNotify()` via `sprintf()` without proper sanitization, but only when the search result count is exactly one. This specific condition bypasses existing global input filters. An unauthenticated remote attacker can exploit this by tricking a user into clicking a crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking (cookie theft) or account takeover. The issue is fixed in version 6.7.0 by applying `htmlspecialchars` to the reflected keywords.
Affected products
- CubeCart CubeCart 6.x prior to 6.7.0
Timeline
- 2026-04-29: advisory: GitHub Security Advisory published
- 2026-05-13: disclosed: CVE published to NVD