Article

    Cyber News / Article / Vulnerability in Quick.Cart software

    Vulnerability in Quick.Cart software
    CE
    CERT Polska-2026-07-28

    Vulnerability in Quick.Cart software

    CERT Polska has received a report about vulnerability in OpenSolution Quick.Cart software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-41874: Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation.

    The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.

    We thank Karol Czubernat for the responsible vulnerability report.

    Original source