PT-2026-3928 · Unknown · Quick.Cart

Arkadiusz Marta

·

Publicado

2026-01-22

·

Atualizado

2026-02-19

·

CVE-2025-67683

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Quick.Cart version 6.7
Description Quick.Cart is susceptible to a reflected cross-site scripting (XSS) issue through the sSort parameter. An attacker can create a malicious URL that, when accessed, leads to the execution of arbitrary JavaScript code within the victim's browser. The vendor was informed of this issue but did not provide details regarding vulnerable versions. The API endpoint potentially affected is not specified. The vulnerable parameter is sSort.
Recommendations Apply a fix for Quick.Cart version 6.7.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-67683

Produtos afetados

Quick.Cart