Back to overview

CVE-2026-41874

MEDIUM
6.8
CVSS 4.0
Description
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.

Metadata

CVE ID
CVE-2026-41874
State
PUBLISHED
Assigner
CERT-PL
Reserved
2026-04-22 10:35 UTC
Published
2026-07-28 12:02 UTC
Last updated
2026-07-28 19:19 UTC
Primary CWE
CWE-256
CWE-256 Plaintext Storage of a Password
Vendor / Product
OpenSolution / Quick.Cart
Sources
cve.org  ·  NVD

Severity & Metrics

6.8 MEDIUM CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
OpenSolution Quick.Cart 0 ≤ 6.7
Weakness (CWE)
CWESourceDescription
CWE-256 cna CWE-256 Plaintext Storage of a Password
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.8 MEDIUM 4.0 cna CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Back to overview