Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Beniamin Jabłoński

#16660of 55,124
16.7Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-6546
9.8
2026-02-05
Unknown · Quick.Cart · CVE-2026-23796
**Name of the Vulnerable Software and Affected Versions** Quick.Cart version 6.7 Quick.Cart (affected versions not specified) **Description** A user's session identifier can be set before authentication in Quick.Cart. The session ID remains consistent even after authentication, allowing an attacker to fixate a session ID for a victim and subsequently hijack the authenticated session. The vendor was notified of this issue but did not provide details regarding vulnerable version ranges. **Recommendations** Apply a fix for Quick.Cart version 6.7. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-6547
6.9
2026-02-05
Unknown · Quick.Cart · CVE-2026-23797
**Name of the Vulnerable Software and Affected Versions** Quick.Cart version 6.7 Quick.Cart (affected versions not specified) **Description** User passwords are stored in plaintext. An attacker with high privileges can view user passwords on the user editing page. The vendor was notified of this issue but did not provide details regarding vulnerable versions. **Recommendations** Update to a newer version that contains a fix for this vulnerability.