Description
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/07/CVE-2026-41874/
Product product
https://opensolution.org/shopping-cart-quick-cart.html
Scores
CVSS v4
6.8
EPSS
0.0013
EPSS Percentile
3.2%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-256
Status
published
Products (1)
OpenSolution/Quick.Cart
< 6.7
Published
Jul 28, 2026
Tracked Since
Jul 28, 2026