PT-2026-3929 · Unknown · Quick.Cart

Arkadiusz Marta

·

Publicado

2026-01-22

·

Atualizado

2026-02-19

·

CVE-2025-67684

CVSS v4.0

9.4

Crítica

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Quick.Cart version 6.7 Quick.Cart (affected versions not specified)
Description Quick.Cart is susceptible to Local File Inclusion and Path Traversal issues within its theme selection process. A user with sufficient privileges can upload arbitrary file content, with validation limited to the filename extension. This allows an attacker to include and execute uploaded PHP code, potentially leading to Remote Code Execution on the server. The vendor was contacted regarding this issue but did not provide details about vulnerable versions or a response. The API endpoint involved in theme selection is not specified. The vulnerable parameter is not specified. The vulnerable function is not specified.
Recommendations Quick.Cart version 6.7 should be updated when a fix becomes available. For all other affected versions, update when a fix becomes available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-67684

Produtos afetados

Quick.Cart