CVE-2026-41875
MEDIUMQuick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this...
Full CISO analysis pending enrichment.
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Quick.Cart | — | — | No patch |
Do you use Quick.Cart? You're affected.
How severe is it?
What should I do?
No patch available
Monitor for updates. Consider compensating controls or temporary mitigations.
Which compliance frameworks are affected?
Compliance analysis pending. Sign in for full compliance mapping when available.
Frequently Asked Questions
What is CVE-2026-41875?
Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it is easily bypassed by manipulating the referer header. All forms available in this software are potentially vulnerable. This issue was fixed in a patch to version 6.7 published on 09.11.2026, deployments without this patch are still vulnerable
Is CVE-2026-41875 actively exploited?
No confirmed active exploitation of CVE-2026-41875 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-41875?
No patch is currently available. Monitor vendor advisories for updates.
What is the CVSS score for CVE-2026-41875?
No CVSS score has been assigned yet.
What are the technical details?
Original Advisory
Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it is easily bypassed by manipulating the referer header. All forms available in this software are potentially vulnerable. This issue was fixed in a patch to version 6.7 published on 09.11.2026, deployments without this patch are still vulnerable
Weaknesses (CWE)
CWE-352 — Cross-Site Request Forgery (CSRF): The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
- [Architecture and Design] Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. For example, use anti-CSRF packages such as the OWASP CSRFGuard. [REF-330] Another example is the ESAPI Session Management control, which includes a component for CSRF. [REF-45]
- [Implementation] Ensure that the application is free of cross-site scripting issues (CWE-79), because most CSRF defenses can be bypassed using attacker-controlled script.
Source: MITRE CWE corpus.
References
- cert.pl/posts/2026/09/CVE-2026-41875/ third-party-advisory
- opensolution.org/shopping-cart-quick-cart.html product