PT-2026-3928 · Unknown · Quick.Cart
Arkadiusz Marta
·
Publicado
2026-01-22
·
Atualizado
2026-02-19
·
CVE-2025-67683
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Quick.Cart version 6.7
Description
Quick.Cart is susceptible to a reflected cross-site scripting (XSS) issue through the
sSort parameter. An attacker can create a malicious URL that, when accessed, leads to the execution of arbitrary JavaScript code within the victim's browser. The vendor was informed of this issue but did not provide details regarding vulnerable versions. The API endpoint potentially affected is not specified. The vulnerable parameter is sSort.Recommendations
Apply a fix for Quick.Cart version 6.7.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Quick.Cart