CVE-2026-54647 | CubeCart up to 6.7.4 Settings settings.index.inc.php download_expire sql injection
A vulnerability described as problematic has been identified in CubeCart up to 6.7.4. Affected by this vulnerability is an unknown functionality of the file admin/sources/settings.index.inc.php of the component Settings Handler. The manipulation of the argument download_expire results in sql injection.
This vulnerability is identified as CVE-2026-54647. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More