This software does implement simple protection against this type of attack, but it is easily bypassed by manipulating the referer header. All forms available in this software are potentially vulnerable.
This issue was fixed in a patch to version 6.7 published on 09.11.2026, deployments without this patch are still vulnerable
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 29 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it is easily bypassed by manipulating the referer header. All forms available in this software are potentially vulnerable. This issue was fixed in a patch to version 6.7 published on 09.11.2026, deployments without this patch are still vulnerable | |
| Title | Cross-Site Request Forgery in admin panel of Quick.Cart | |
| First Time appeared |
Opensolution
Opensolution quick.cart |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:opensolution:quick.cart:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensolution
Opensolution quick.cart |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-29T15:00:17.846Z
Reserved: 2026-04-22T10:35:11.713Z
Link: CVE-2026-41875
Updated: 2026-09-29T15:00:14.159Z
Status : Received
Published: 2026-09-29T12:17:10.787
Modified: 2026-09-29T15:17:25.810
Link: CVE-2026-41875
No data.
OpenCVE Enrichment
No data.