Junglewise Threat Intelligence

CVE-2026-45708: CubeCart PHP code injection in Invoice Editor

CVE-2026-45708 · Severity: high · CVSS 7.2 · Published 2026-05-13

Technologies: CubeCart. Vendors: CubeCart.

Executive brief

CubeCart is an e-commerce platform used to manage online stores. A security flaw allows an administrative user with permission to edit documents to inject malicious code into the invoice template. When any administrator later prints an order, the system generates a temporary file containing this code that is accessible to anyone on the internet, potentially allowing an attacker to take full control of the web server and access sensitive customer data.

Technical details

A code injection vulnerability exists in CubeCart's Invoice Editor (admin/sources/documents.invoice.inc.php) where the application reads from $GLOBALS['RAW']['POST']['content'], bypassing global HTML sanitization. While Smarty security policies are in place, they do not filter raw PHP tags (<?php ... ?>). When an administrator prints an order, the rendered template—including the raw PHP—is written to a file named 'print.<md5>.php' in the /files/ directory. Due to an explicit 'allow from all' directive in the files/.htaccess for print.*.php files, these files become publicly accessible. An attacker can then execute arbitrary code with the privileges of the web server user. This is fixed in version 6.7.3 by stripping PHP tags before writing the print artifact.

Affected products

  • CubeCart CubeCart < 6.7.3

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-05-13: disclosed: NVD publication date
  • 2026-05-13: patched: Fixed in version 6.7.3

References

Related threats