CVE-2026-41874

Severity CVSS v4.0:
MEDIUM
Type:
CWE-256 Plaintext Storage of a Password
Publication date:
28/07/2026
Last modified:
30/07/2026

Description

Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation.<br /> <br /> <br /> The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.<br /> <br /> <br /> <br /> Only version 6.7 was tested but all versions should be considered as vulnerable.