File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/cubecart/v6 | product |
https://forums.cubecart.com/topic/59046-cubecart-655-released-minor-security-update/ | release notes |
https://github.com/julio-cfa/CVE-2024-33438 | broken link third party advisory exploit |
https://github.com/cubecart/v6/commit/31a5ec39b0924b2111fbc3aa419bd8c5c3fc1841 | patch |