[webapps] CubeCart 6.7.4 - SQL injection
# Exploit Title: CubeCart 6.7.4 - SQL injection# 2026-8-31 00:0:0 Author: www.exploit-db.com(查看原文) 阅读量:2 收藏

# Exploit Title: CubeCart 6.7.4 - SQL injection
# Date: 2026-06-08
# Exploit Author: Mikail Kocadağ
# Vendor Homepage: https://www.cubecart.com/
# Software Link: https://github.com/cubecart/v6
# Vulnerable Version: 6.7.4
# Fixed Version: 6.7.5
# CVE: CVE-2026-54647
# Advisory / References:
https://github.com/cubecart/v6/security/advisories/GHSA-hvmw-v8gc-4c29

--------------------------------------------------------------------------------
VULNERABILITY SUMMARY
--------------------------------------------------------------------------------
An authenticated administrative SQL injection vulnerability exists in
CubeCart v6.7.4
due to unsafe concatenation of user-supplied input in raw database queries
without validation.

The vulnerability is located in `admin/sources/settings.index.inc.php` at
line 184.
The `download_expire` parameter received via POST is directly concatenated
into an
`UPDATE` SQL statement executed via `query()` or `misc()`.

The global input sanitizer (`Sanitize::_safety()`) relies entirely on
`htmlspecialchars()`,
which does not filter or encode commas (`,`). An attacker can leverage
comma injection
to break out of the intended syntax and manipulate the `SET` clauses or
append malicious clauses.

--------------------------------------------------------------------------------
IMPACT
--------------------------------------------------------------------------------
An authenticated attacker with access to settings can manipulate arbitrary
columns
within the settings tables or potentially perform lateral movement within
the database.

--------------------------------------------------------------------------------
PROOF OF CONCEPT (PoC)
--------------------------------------------------------------------------------
1. Authenticated as an administrator, navigate to Settings.
2. Intercept the save request and inject a payload containing a comma into
the `download_expire` field:

   1, expire=0 WHERE 1=1-- -

3. Submit the request and verify that the raw SQL syntax is successfully
altered.
            

文章来源: https://www.exploit-db.com/exploits/52664
如有侵权请联系:admin#unsafe.sh