Local File Inclusion and Path Traversal in Quick.Cart by OpenSolution
CVE-2025-67684

9.4CRITICAL

Key Information:

Vendor
CVE Published:
22 January 2026

What is CVE-2025-67684?

Quick.Cart is susceptible to Local File Inclusion and Path Traversal vulnerabilities within its theme selection mechanism. This issue arises when a privileged user is allowed to upload files without proper validation, only checking the filename extension. Consequently, this flaw opens the door for an attacker to upload and execute arbitrary PHP code. As a result, the server may be compromised, allowing for Remote Code Execution. The vulnerability has been confirmed in version 6.7, but there is a possibility that other versions could also be affected, as they have not been thoroughly tested.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Quick.Cart 6.7

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arkadiusz Marta
.