{"id":"CVE-2026-54646","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-54646","summary":"CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and…","details":"CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE statements without validating the identifiers or escaping embedded backticks. An authenticated administrator can terminate the quoted identifier with a closing backtick and introduce attacker-controlled structural SQL, potentially compromising database confidentiality, integrity, and availability within the application's database privileges. This issue is fixed in version 6.7.5.","published":"2026-09-17T22:01:53.897Z","modified":"2026-09-17T22:01:53.897Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/cubecart/v6/commit/fc08d55628191969f2345d06d862df316f7d44d3","label":"cubecart/v6@fc08d55"},"references":[{"type":"WEB","url":"https://github.com/cubecart/v6/security/advisories/GHSA-qcx6-cg43-ffmx"},{"type":"WEB","url":"https://github.com/cubecart/v6/commit/fc08d55628191969f2345d06d862df316f7d44d3"},{"type":"WEB","url":"https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php"},{"type":"WEB","url":"https://github.com/cubecart/v6/releases/tag/6.7.5"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T22:01:53.897Z"}}