Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Beniamin Jabłoński

#16143de 53,640
16.7CVSS total
Vulnerabilidades · 2
Média
1
Crítica
1
PT-2026-6546
9.8
2026-02-05
Unknown · Quick.Cart · CVE-2026-23796
**Name of the Vulnerable Software and Affected Versions** Quick.Cart version 6.7 Quick.Cart (affected versions not specified) **Description** A user's session identifier can be set before authentication in Quick.Cart. The session ID remains consistent even after authentication, allowing an attacker to fixate a session ID for a victim and subsequently hijack the authenticated session. The vendor was notified of this issue but did not provide details regarding vulnerable version ranges. **Recommendations** Apply a fix for Quick.Cart version 6.7. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-6547
6.9
2026-02-05
Unknown · Quick.Cart · CVE-2026-23797
**Name of the Vulnerable Software and Affected Versions** Quick.Cart version 6.7 Quick.Cart (affected versions not specified) **Description** User passwords are stored in plaintext. An attacker with high privileges can view user passwords on the user editing page. The vendor was notified of this issue but did not provide details regarding vulnerable versions. **Recommendations** Update to a newer version that contains a fix for this vulnerability.