PT-2026-102507 · Unknown · Quick.Cart
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Quick.Cart versions prior to 6.7 patch published on 09.11.2026
Description
The admin config panel is susceptible to Cross-Site Request Forgery (CSRF), a flaw where an attacker tricks a victim into performing actions they did not intend to. A malicious actor can create a website that, when visited by an administrator, automatically sends a POST request to change the administrator's login and password. Although the software includes basic protection, it can be bypassed by manipulating the referer header. All forms within the software are potentially affected.
Recommendations
Apply the patch for version 6.7 published on 09.11.2026.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quick.Cart