CVE-2026-54647 | CubeCart up to 6.7.4 Settings settings.index.inc.php download_expire sql injection

SecurityVulns

A vulnerability described as problematic has been identified in CubeCart up to 6.7.4. Affected by this vulnerability is an unknown functionality of the file admin/sources/settings.index.inc.php of the component Settings Handler. The manipulation of the argument download_expire results in sql injection.

This vulnerability is identified as CVE-2026-54647. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More