CVE-2026-45055CWE-20CWE-345CWE-601CWE-784

CubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host Header

High · published May 13, 2026

CVSS v3.1
8.1
EPSS
0%
Percentile
4.3
In the wild
Unconfirmed
What it is

CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the Host request header at bootstrap, with no allowlist. The constant is embedded verbatim into transactional email links, most critically the password-reset link in User::passwordRequest() (and the admin equivalent in Admin::passwordRequest()). An unauthenticated attacker who knows a target email can POST /index.php?_a=recover with Host: evil.com; CubeCart writes a fresh verify token (valid 3,600 s) and emails the victim a link http://evil.com/index.php?_a=recovery&validate=<TOKEN>. The token is valid against the legitimate store — capturing the victim's click on evil.com yields full account takeover, or store takeover when an admin email is targeted. This vulnerability is fixed in 6.7.2.

The record
Technical detail
CVSS v3.1
8.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00147 · 4.3th percentile
Weaknesses
CWE-20 · Improper Input Validation; CWE-345 · Insufficient Verification of Data Authenticity; CWE-601 · URL Redirection to Untrusted Site ('Open Redirect'); CWE-784 · Reliance on Cookies without Validation and Integrity Checking in a Security Decision
Published
2026-05-13T20:44Z
EPSS history
Timeline
  • 13 MAY 20:44Z
    CubeCart: Pre-Authenticated Password Reset Link Poisoning via HTTP Host Header
    cvelistv5