Junglewise Threat Intelligence

CVE-2026-54647: CubeCart SQL injection in download_expire settings parameter

CVE-2026-54647 · Severity: high · CVSS 7.2 · Published 2026-09-17

Technologies: CubeCart. Vendors: CubeCart.

Executive brief

CubeCart is a popular e-commerce platform that allows merchants to sell products online. An authenticated administrator can exploit a SQL injection vulnerability in the download expiration settings to modify database records beyond the intended scope, potentially exposing or altering customer data, product information, or store configuration. The vulnerability has been fixed in version 6.7.5.

Technical details

The vulnerability is a SQL injection (SQLi) in the admin settings panel, specifically in admin/sources/settings.index.inc.php. The download_expire POST parameter is directly concatenated into an UPDATE statement for the CubeCart_downloads table without numeric validation or parameterized queries. An authenticated administrator can supply a comma-delimited payload to modify the SQL SET clause, manipulating additional database columns. The vulnerability requires an existing admin session (authenticated attack) and was patched by casting the parameter to an integer before SQL concatenation, ensuring only numeric values are accepted.

Affected products

  • CubeCart CubeCart prior to 6.7.5

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Fixed in version 6.7.5

References

Related threats