# CERT Polska discloses Quick.Cart admin CSRF flaw

Published: 2026-09-29 · Severity: routine · Sectors: retail
Canonical: https://vorant.io/reports/ca8b2a8c-050a-5e3c-84d1-167323efb396/cert-polska-discloses-quick-cart-admin-csrf-flaw

> A CSRF bug in Quick.Cart's admin panel lets attackers silently change the admin's login and password; patched in version 6.7.

CERT Polska coordinated disclosure of CVE-2026-41875, a Cross-Site Request Forgery vulnerability in the Quick.Cart shopping cart platform's admin configuration panel. An attacker can craft a malicious webpage that, when visited by an authenticated admin, silently submits a POST request that overwrites the admin's login credentials, effectively granting the attacker full control of the store's backend. Quick.Cart includes a basic anti-CSRF check, but it relies on the Referer header, which can be trivially manipulated or stripped by an attacker, rendering the protection ineffective. CERT Polska notes that all forms in the application are potentially affected by the same weakness, not just the credential-change form.

The vendor fixed the issue in Quick.Cart version 6.7, released 9 November 2026. Any deployment running an earlier version remains vulnerable. There is no indication in the report of active exploitation in the wild; this is a coordinated disclosure following a report from researcher Karol Czubernat.

Defenders operating Quick.Cart instances should upgrade to 6.7 or later immediately. Until patched, mitigations include restricting admin panel access by IP/VPN, deploying a properly token-based (not Referer-based) CSRF defense via a WAF, and monitoring for unexpected admin credential changes or suspicious POST requests to the config panel from unusual referring domains.

## Mentioned in this report

- Vulnerabilities: CVE-2026-41875

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-41875

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ca8b2a8c-050a-5e3c-84d1-167323efb396/cert-polska-discloses-quick-cart-admin-csrf-flaw.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
