OpenSolution Quick.Cart version 6.7 contains a CSRF vulnerability (CVE-2025-10317)…
OpenSolution Quick.Cart version 6.7 contains a CSRF vulnerability (CVE-2025-10317) allowing attackers to create malicious products via admin session hijacking.
CERT Polska has coordinated disclosure of CVE-2025-10317, a Cross-Site Request Forgery vulnerability affecting OpenSolution Quick.Cart e-commerce software. The vulnerability allows an attacker to craft a malicious website that, when visited by an authenticated administrator, automatically submits a POST request creating a product with attacker-controlled content. The software lacks CSRF protection mechanisms across its forms, suggesting a systemic security control gap.
Version 6.7 was confirmed vulnerable during testing, though the vendor did not respond with details about the full range of affected versions. CERT Polska notes that all forms in the application are potentially vulnerable to similar CSRF attacks. The vulnerability was responsibly disclosed by security researcher Łukasz Woźniak.
While CSRF vulnerabilities typically require social engineering to exploit, the lack of basic protection in an e-commerce platform represents a significant security oversight. Organizations running Quick.Cart should assess their exposure and monitor for vendor patches, though vendor engagement appears limited based on the disclosure timeline.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2025/10/CVE-2025-10317
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free