HIGH8.8
GHSA-h5q8-5697-9p9h
Cross-Site Request Forgery in express-cart
Quick fix
GHSA-h5q8-5697-9p9h — express-cart: upgrade to the fixed version with the command below.
npm install express-cart@1.1.17Details
The express-cart package through 1.1.10 for Node.js allows CSRF.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-22403[ADVISORY]
- https://github.com/mrvautin/expressCart/issues/120[WEB]
- https://github.com/mrvautin/expressCart/commit/cd3ba1bc609c2f2946bfbc7ee2fccf3483eb71fb[WEB]
- https://hackerone.com/reports/395944[WEB]
- https://github.com/mrvautin/expressCart[PACKAGE]
- https://security.netapp.com/advisory/ntap-20210909-0004[WEB]
- https://www.npmjs.com/package/express-cart[WEB]