7.1

CVE-2025-59335

Exploit

CubeCart Session Not Invalidated After Password Change

CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a location where they accessed their account, an unauthorized user can maintain access even after the password has been changed. Due to this bug, if an account has already been compromised, the legitimate user has no way to revoke the attacker’s access. The malicious actor retains full access to the account until their session naturally expires. This means the account remains insecure even after the password has been changed. This issue has been patched in version 6.5.11.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CubecartCubecart Version < 6.5.11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.087
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-613 Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

https://github.com/cubecart/v6/security/advisories/GHSA-4vwh-x8m2-fmvv
Vendor Advisory
Exploit
https://github.com/cubecart/v6/commit/4bfaeb4485dd82255a108940a163af5ba4583b52
Patch
https://github.com/cubecart/v6/commit/62d9be8416aa6fd7343f8932d98c5b112b163e26
Patch