6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Description
CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the force_unsubscribe parameter in the POST request to 1, an attacker can force the removal of any valid subscriberโs email address. This issue has been patched in version 6.5.11.
Basic Information
ID
CVE-2025-59413
Source
GitHub_M
Published
Sep 22, 2025 at 16:15
Modified
Sep 22, 2025 at 17:26
Affected Product
Vendor
cubecart
Product
v6
Version
< 6.5.11
Affected Versions
cubecart v6 < 6.5.11