VDB
Sign up
HIGH8.8

GHSA-4w62-cq5r-5mmq

express-cart unrestricted file upload vulnerability

Quick fix

GHSA-4w62-cq5r-5mmq — express-cart: upgrade to the fixed version with the command below.

npm install express-cart@1.1.7

Details

Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express-cart
Introduced in: 0Fixed in: 1.1.7
Fixnpm install express-cart@1.1.7

References