CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a location where they accessed their account, an unauthorized user can maintain access even after the password has been changed. Due to this bug, if an account has already been compromised, the legitimate user has no way to revoke the attacker’s access. The malicious actor retains full access to the account until their session naturally expires. This means the account remains insecure even after the password has been changed. This issue has been patched in version 6.5.11.
History

Tue, 23 Sep 2025 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:cubecart:cubecart:*:*:*:*:*:*:*:*

Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Cubecart
Cubecart cubecart
Vendors & Products Cubecart
Cubecart cubecart

Mon, 22 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 16:30:00 +0000

Type Values Removed Values Added
Description CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a location where they accessed their account, an unauthorized user can maintain access even after the password has been changed. Due to this bug, if an account has already been compromised, the legitimate user has no way to revoke the attacker’s access. The malicious actor retains full access to the account until their session naturally expires. This means the account remains insecure even after the password has been changed. This issue has been patched in version 6.5.11.
Title CubeCart Session Not Invalidated After Password Change
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-22T16:13:23.838Z

Updated: 2025-09-22T17:26:51.453Z

Reserved: 2025-09-12T12:36:24.635Z

Link: CVE-2025-59335

cve-icon Vulnrichment

Updated: 2025-09-22T16:54:04.962Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-22T17:16:08.527

Modified: 2025-09-23T16:51:42.487

Link: CVE-2025-59335

cve-icon Redhat

No data.