CVE-2026-41875

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it is easily bypassed by manipulating the referer header. All forms available in this software are potentially vulnerable. This issue was fixed in a patch to version 6.7 published on 09.11.2026, deployments without this patch are still vulnerable

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
Full discourse1 post
  • bdddr@higgrv69

    Opublikowałem exploita do CVE-2026-41875, oneclick account takeover w Quick.Cart, największym darmowym polskim systemie ecommerce i prawdopodobnie 2 wśród wszystkich polskich platform tego typu (mam na myśli darmowe i polskie). Exploit dostępny na GitHubie https://github.com/hhg69/CVE-2026-41875-EXPLOIT-QuickCart-one-click-Account-Takeover

    3003083
    23 followersView on X

Explore more