CVE-2026-41874
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Jul 28, 2026
Vendor
unknown
Description
Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with access to the server file system to retrieve authentication details, potentially leading to privilege escalation. The vendor assessed the likelihood of exploitation as very low and determined that a fix isΒ not necessary. Only version 6.7 was tested but all versions should be considered as vulnerable.