VDB
Sign up
HIGH8.8

GHSA-h5q8-5697-9p9h

Cross-Site Request Forgery in express-cart

Quick fix

GHSA-h5q8-5697-9p9h — express-cart: upgrade to the fixed version with the command below.

npm install express-cart@1.1.17

Details

The express-cart package through 1.1.10 for Node.js allows CSRF.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express-cart
Introduced in: 0Fixed in: 1.1.17
Fixnpm install express-cart@1.1.17

References