The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to unserialize arbitrary PHP objects via a crafted shipping parameter, as demonstrated by modifying the application configuration using the Config object.
Score: 0.0
Priority: Unclassified
Score: 0.3101
Percentile:
0.9653
CVSS v3.1 Score: 9.8
Severity: CRITICAL