HIGH8.8
GHSA-hr89-w7p6-pjmq
express-cart allows any user to create an admin user
Quick fix
GHSA-hr89-w7p6-pjmq — express-cart: upgrade to the fixed version with the command below.
npm install express-cart@1.1.6Details
Express-Cart before 1.1.6 allows remote attackers to create an admin user via an `/admin/setup` Referer header.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-12457[ADVISORY]
- https://github.com/mrvautin/expressCart/commit/baccaae9b0b72f00b10c5453ca00231340ad3e3b[WEB]
- https://hackerone.com/reports/343626[WEB]
- https://github.com/mrvautin/expressCart[PACKAGE]
- https://github.com/nodejs/security-wg/blob/main/vuln/npm/469.json[WEB]
- https://snyk.io/vuln/npm:express-cart:20180712[WEB]
- https://www.npmjs.com/advisories/730[WEB]
- https://www.npmjs.com/package/express-cart?activeTab=versions[WEB]