PT-2026-102507 · Unknown · Quick.Cart

·

CVE-2026-41875

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quick.Cart versions prior to 6.7 patch published on 09.11.2026
Description The admin config panel is susceptible to Cross-Site Request Forgery (CSRF), a flaw where an attacker tricks a victim into performing actions they did not intend to. A malicious actor can create a website that, when visited by an administrator, automatically sends a POST request to change the administrator's login and password. Although the software includes basic protection, it can be bypassed by manipulating the referer header. All forms within the software are potentially affected.
Recommendations Apply the patch for version 6.7 published on 09.11.2026.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41875

Affected Products

Quick.Cart