CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews feature where user-supplied input is not properly sanitized before being displayed. An attacker can submit HTML tags inside the review description field. Once the administrator approves the review, the injected HTML is rendered on the product page for all visitors. This could be used to redirect users to malicious websites or to display unwanted content. This issue has been patched in version 6.5.11.
History

Tue, 23 Sep 2025 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:cubecart:cubecart:*:*:*:*:*:*:*:*

Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Cubecart
Cubecart cubecart
Vendors & Products Cubecart
Cubecart cubecart

Mon, 22 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 16:30:00 +0000

Type Values Removed Values Added
Description CubeCart is an ecommerce software solution. Prior to version 6.5.11, a vulnerability exists in the product reviews feature where user-supplied input is not properly sanitized before being displayed. An attacker can submit HTML tags inside the review description field. Once the administrator approves the review, the injected HTML is rendered on the product page for all visitors. This could be used to redirect users to malicious websites or to display unwanted content. This issue has been patched in version 6.5.11.
Title CubeCart Vulnerable to HTML Injection in Product Reviews Allows Malicious Links and Defacement
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-09-22T17:26:36.393Z

Reserved: 2025-09-15T19:13:16.903Z

Link: CVE-2025-59412

cve-icon Vulnrichment

Updated: 2025-09-22T16:53:39.388Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-22T17:16:08.880

Modified: 2025-09-23T16:50:51.817

Link: CVE-2025-59412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-23T16:09:14Z