Vulnerabilities in Quick.Cart software (opens in new tab)

Vulnerabilities in Quick.Cart software

CVE IDCVE-2025-67683
Publication date22 January 2026
VendorOpenSolution
ProductQuick.Cart
Vulnerable versions6.7
Vulnerability type (CWE)Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’) (CWE-79)
Report sourceReport to CERT Polska
CVE IDCVE-2025-67684
Publication date22 January 2026
VendorOpenSolution
ProductQuick.Cart
Vulnerable versions6.7
Vulnerability type (CWE)Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) (CWE-22)
Report sourceReport to CERT Polska

Description

CERT Polska has received a report about vulnerabilities in OpenSolution Quick.Cart software and participated in coordination of their disclosure.

The vulnerability CVE-2025-67683: Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary JavaScript execution in the victim’s browser.

The vulnerability CVE-2025-67684: Quick.Cart is vulnerable to Local File Inclusion and Path Traversal issues in the theme selection mechanism. Quick.Cart allows a privileged user to upload arbitrary file contents while only validating the filename extension. This allows an attacker to include and execute uploaded PHP code, resulting in Remote Code Execution on the server.

The vendor was notified early about these vulnerabilities, but didn’t respond with the details of vulnerabilities or vulnerable version range. Only version 6.7 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

Credits

We thank Arkadiusz Marta for the responsible vulnerability report.


More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Save / unsave
s
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help