Executive brief
CubeCart is an e-commerce platform used by businesses to manage online stores and process customer orders. A security flaw in the software's file management system allows an authorized user or integrated third-party service to upload malicious code to the server. If exploited, an attacker could take full control of the online store, steal sensitive customer data, exfiltrate payment information, or disrupt business operations.
Technical details
An arbitrary file upload vulnerability exists in the REST API File Manager endpoint (POST /api/v1/files) of CubeCart due to insufficient validation in 'classes/api/resources/apiresource_files.class.php'. The application fails to restrict executable file extensions and does not invoke standard security validators, allowing PHP files to be uploaded to the web-accessible 'images/source/' directory. Furthermore, a path traversal flaw in the 'filepath' parameter allows attackers to escape the intended directory and write files to the document root. An attacker with an API key possessing 'files:rw' permissions can exploit these flaws to achieve remote code execution (RCE). The vulnerability is fixed in version 6.7.0.
Affected products
- CubeCart CubeCart 6.6.x, prior to 6.7.0
Timeline
- 2026-05-07: advisory: Original GitHub security advisory published
- 2026-05-13: disclosed: CVE published to NVD