CVE-2026-41874
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-256
Almacenamiento de un contraseña en texto claro
Fecha de publicación:
28/07/2026
Última modificación:
30/07/2026
Descripción
*** Pendiente de traducción *** Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation.<br />
<br />
<br />
The vendor assessed the likelihood of exploitation as very low and determined that a fix is not necessary.<br />
<br />
<br />
<br />
Only version 6.7 was tested but all versions should be considered as vulnerable.
Impacto
Puntuación base 4.0
6.80
Gravedad 4.0
MEDIA



