Quick.Cart 的管理配置面板存在跨站请求伪造(CSRF)漏洞。恶意攻击者可以构造一个特殊网站,当管理员访问该网站时,网站会自动向 Quick.Cart 发送一个 POST 请求,从而修改管理员的登录名和密码。 虽然该软件针对此类攻击提供了一定的防护机制,但攻击者可以通过篡改 Referer 请求头轻松绕过这些防护。该软件中所有可用的表单均可能存在此漏洞。 该漏洞已在 2026 年 11 月 9 日发布的 6.7 版本补丁中得到修复,未应用该补丁的部署环境仍存在此安全风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenSolution | Quick.Cart | 0 ~ 6.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet