Posted by Andrey Stoykov on Jun 03
# Exploit Title: Stored XSS in “Description” Functionality – cubecartv6.5.9
# Date: 05/2025
# Exploit Author: Andrey Stoykov
# Version: 6.5.9
# Tested on: Debian 12
# Blog: https://msecureltd.blogspot.com/
Stored XSS #1:
Steps to Reproduce:
1. Visit “Account” > “Address Book” and choose “Edit”
2. In the “Description” parameter enter the following payload…
– Read More – Full Disclosure