The Cubecart::_basket method in classes/cubecart.class...
High severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 17, 2024
Description
Published by the National Vulnerability Database
Feb 8, 2013
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jan 17, 2024
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
References