CVE-2025-59413: CubeCart Unauthorized Newsletter Unsubscription via force_unsubscribe Parameter
CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the forceunsubscribe parameter in the POST request to 1, an attacker can force the removal of any valid subscriber’s email address. This issue has been patched in version 6.5.11.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59413?
CVE-2025-59413 is classified as a moderate severity vulnerability due to the potential unauthorized unsubscription of users from newsletters.
How do I fix CVE-2025-59413?
To fix CVE-2025-59413, upgrade CubeCart to version 6.5.11 or later.
What type of vulnerability is CVE-2025-59413?
CVE-2025-59413 is a logic flaw in the newsletter subscription endpoint of CubeCart.
Who is affected by CVE-2025-59413?
Users of CubeCart versions prior to 6.5.11 are affected by CVE-2025-59413.
What can an attacker do with CVE-2025-59413?
An attacker can misuse CVE-2025-59413 to unsubscribe any user from newsletters without their consent.