Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-41875— Cross-Site Request Forgery in admin panel of Quick.Cart

Quick assessment

Affected
OpenSolution Quick.Cart
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Quick.Cart 的管理配置面板存在跨站请求伪造(CSRF)漏洞。恶意攻击者可以构造一个特殊网站,当管理员访问该网站时,网站会自动向 Quick.Cart 发送一个 POST 请求,从而修改管理员的登录名和密码。 虽然该软件针对此类攻击提供了一定的防护机制,但攻击者可以通过篡改 Referer 请求头轻松绕过这些防护。该软件中所有可用的表单均可能存在此漏洞。 该漏洞已在 2026 年 11 月 9 日发布的 6.7 版本补丁中得到修复,未应用该补丁的部署环境仍存在此安全风险。

CVSS 6.9 · Medium

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-41875

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cross-Site Request Forgery in admin panel of Quick.Cart
Source: CVE Program / CVE List V5
Vulnerability Description
Quick.Cart is vulnerable to Cross-Site Request Forgery in admin config panel. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request that changes admin's login and password. This software does implement simple protection against this type of attack, but it is easily bypassed by manipulating the referer header. All forms available in this software are potentially vulnerable. This issue was fixed in a patch to version 6.7 published on 09.11.2026, deployments without this patch are still vulnerable
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenSolution Quick.Cart 0 ~ 6.7.0 -

II. Public POCs for CVE-2026-41875

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-41875

请登录查看更多情报信息。

Security Blog Posts for CVE-2026-41875 (1)

Other References for CVE-2026-41875 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-41875

No comments yet


Leave a comment