Home
MEDIUM: 6.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:LMEDIUM: 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N prior to 6.6.0
affected
Description
An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQL statement on the product.
Problem types
Improper neutralization of special elements used in an SQL command ('SQL Injection')
Product status
References
community.cubecart.com/...-the-biggest-update-in-years/62405