CVE-2026-23797Disclosure(opensolution / quick.cart)

LOWCVSS 4.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password in user editing page. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-256

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • quick.cart

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
quick.cart

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-05: 2Technical Details · 2026-02-05: 202-05
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-23797 In Quick.Cart user passwords are stored in plaintext form. An attacker with high privileges can display users' password in user editing page. The vendor was notified… https://www.cve.org/CVERecord?id=CVE-2026-23797

    Post summary

    Quick.Cart stores user passwords in plaintext, allowing high-privilege attackers to view them via the user editing page. The vendor has been notified and a CVE record is available.

    00010254
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-23797 Quick.Cart Privilege Escalation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23797

    Post summary

    The text references CVE‑2026‑23797 for Quick.Cart privilege escalation and links to a vulnerability page, but does not provide PoC, exploit code, patch, or active exploitation information.

    0000064
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensolutionquick.cart6.7--

Explore more