CVE-2026-41875
Received Received - Intake

Cross-Site Request Forgery in Quick.Cart Admin Panel

Vulnerability report for CVE-2026-41875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: CERT.PL

Description

Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it is easily bypassed by manipulating the referer header. All forms available in this software are potentially vulnerable. This issue was fixed in a patch to version 6.7 published on 09.11.2026, deployments without this patch are still vulnerable

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
quick_cart quick_cart From 6.7 (exc)
opensolution quick.cart From 6.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Quick.Cart has a Cross-Site Request Forgery (CSRF) vulnerability in its admin configuration panel. An attacker can create a malicious website that, when visited by an admin, automatically sends a POST request to change the admin's login credentials. The software has basic CSRF protection but it can be bypassed by manipulating the referer header. All forms in the software are potentially vulnerable.

Detection Guidance

Detecting this CSRF vulnerability requires checking if the admin config panel forms are vulnerable to referer header manipulation. Inspect network traffic for POST requests from admin interfaces without proper CSRF tokens or referer validation. Monitor for unexpected changes in admin credentials or config settings.

Impact Analysis

If you are an admin of a Quick.Cart site, an attacker could trick you into visiting a malicious site and change your login credentials. This would allow the attacker to gain full control of your admin panel, potentially leading to unauthorized access, data theft, or further compromise of your online store.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive customer data, violating GDPR and HIPAA requirements for data protection and access control. A breach may result in legal penalties, loss of customer trust, and non-compliance with regulatory standards.

Mitigation Strategies

Immediately update Quick.Cart to version 6.7 or later to apply the security patch. If updating is not possible, disable the admin config panel or restrict access to trusted IP addresses. Implement additional CSRF protections like strict referer checking or CAPTCHA on admin forms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-41875. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart