CVE 6.5 MEDIUM

CubeCart Unauthorized Newsletter Unsubscription via force_unsubscribe Parameter_CVE-2025-59413

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Description

CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the force_unsubscribe parameter in the POST request to 1, an attacker can force the removal of any valid subscriberโ€™s email address. This issue has been patched in version 6.5.11.

Basic Information

ID CVE-2025-59413
Source GitHub_M
Published Sep 22, 2025 at 16:15
Modified Sep 22, 2025 at 17:26

Affected Product

Vendor cubecart
Product v6
Version < 6.5.11
Affected Versions cubecart v6 < 6.5.11

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.