Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to obtain files in the system.
https://jvn.jp/en/jp/JVN22220399/
https://forums.cubecart.com/topic/58736-cubecart-653-released-security-update/