Reflected XSS Vulnerability in Quick.Cart by OpenSolution
CVE-2025-67683
5.1MEDIUM
What is CVE-2025-67683?
Quick.Cart, a web development tool by OpenSolution, is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability through the sSort parameter. This flaw permits an attacker to construct a malicious URL that, when accessed by a victim, can lead to unauthorized execution of JavaScript within the victim's browser. The vendor was informed of this issue; however, there has been no disclosure regarding the details of the vulnerability or the scope of affected versions. While version 6.7 has been confirmed as vulnerable, other versions have not been evaluated and may also possess the same vulnerability.
Affected Version(s)
Quick.Cart 6.7
