File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.
https://github.com/julio-cfa/CVE-2024-33438
https://github.com/cubecart/v6/commit/31a5ec39b0924b2111fbc3aa419bd8c5c3fc1841
https://github.com/cubecart/v6
https://forums.cubecart.com/topic/59046-cubecart-655-released-minor-security-update/