Description
CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the force_unsubscribe parameter in the POST request to 1, an attacker can force the removal of any valid subscriber’s email address. This issue has been patched in version 6.5.11.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Affected products
- cubecart / v6< 6.5.11 – < 6.5.11
References
- VENDOR_ADVISORYhttps://github.com/cubecart/v6/security/advisories/GHSA-869v-gjv8-9m7f
- PATCHhttps://github.com/cubecart/v6/commit/7fd1cd04f5d5c3ce1d7980327464f0ff6551de79
- PATCHhttps://github.com/cubecart/v6/commit/db965fcfa260c4f17eb16f8c5494e5af4a8ac271
- PATCHhttps://github.com/cubecart/v6/commit/dbc58cf1f7a6291f7add5893b56bff7920a29128
Updated 5m ago · 8 sources