Full Report
Cross-Site Request Forgery (CSRF) vulnerability (CVE-2026-41875) has been found in Quick.Cart software.
Analysis Summary
# Vulnerability: Cross-Site Request Forgery (CSRF) in Quick.Cart Admin Panel
## CVE Details
- **CVE ID:** CVE-2026-41875
- **CVSS Score:** Not explicitly provided in the source (Estimated High based on impact)
- **CWE:** CWE-352 (Cross-Site Request Forgery)
## Affected Systems
- **Products:** OpenSolution Quick.Cart
- **Versions:** All versions through 6.7.0 (specifically those deployed before November 9, 2026)
- **Configurations:** Admin configuration panel access
## Vulnerability Description
Quick.Cart is vulnerable to a Cross-Site Request Forgery (CSRF) flaw within its administrative configuration panel. While the software implements a basic protection mechanism against such attacks, the defense is flawed as it relies on Referer header validation which can be easily bypassed. An attacker can leverage this flaw to perform unauthorized actions by tricking an authenticated administrator into visiting a malicious website.
## Exploitation
- **Status:** PoC availability implied (crafting of special websites for POST requests described); coordination handled by CERT Polska.
- **Complexity:** Low (Simple bypass of Referer header validation).
- **Attack Vector:** Network (Web-based).
## Impact
- **Confidentiality:** Low/Medium
- **Integrity:** High (Allows unauthorized modification of admin credentials).
- **Availability:** High (Potential for account lockout/takeover).
- **Summary:** A successful attack allows a remote actor to automatically send a POST request that changes the administrator's login and password, leading to complete takeover of the store management.
## Remediation
### Patches
- **Quick.Cart v6.7 Patch:** A specific security patch for version 6.7 was published on **November 9, 2026**. Users should ensure this specific patch is applied to their installation.
### Workarounds
- The source does not list specific workarounds; however, administrators should avoid browsing external websites while logged into the Quick.Cart admin panel until the patch is applied.
## Detection
- **Indicators of Compromise:** Unexpected changes to administrative login credentials or configuration settings.
- **Detection Methods:** Inspecting web server logs for unauthorized POST requests to admin configuration endpoints that lack valid referer headers or originate from unexpected sources.
## References
- **Vendor:** OpenSolution
- **Advisory Link:** hxxps[://]cert[.]pl/en/posts/2026/09/CVE-2026-41875/
- **CVE Link:** hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-41875
- **CVD Policy:** hxxps[://]cert[.]pl/en/cvd/