Loading...
Loading...
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete orders via an orders-delete action to admin.php, and possibly (2) delete products or (3) delete pages via unspecified vectors.
December 1, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-4120
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.