CVE 7.1 HIGH

CubeCart Session Not Invalidated After Password Change_CVE-2025-59335

7.1 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration following a user's password change. This oversight poses a security risk, as if a user forgets to log out from a location where they accessed their account, an unauthorized user can maintain access even after the password has been changed. Due to this bug, if an account has already been compromised, the legitimate user has no way to revoke the attacker’s access. The malicious actor retains full access to the account until their session naturally expires. This means the account remains insecure even after the password has been changed. This issue has been patched in version 6.5.11.

Basic Information

ID CVE-2025-59335
Source GitHub_M
Published Sep 22, 2025 at 16:13
Modified Sep 22, 2025 at 17:26

Affected Product

Vendor cubecart
Product v6
Version < 6.5.11
Affected Versions cubecart v6 < 6.5.11

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.