expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://www.npmjs.com/package/express-cart?activeTab=versions | third party advisory |
https://hackerone.com/reports/343626 | issue tracking third party advisory |
https://github.com/mrvautin/expressCart/commit/baccaae9b0b72f00b10c5453ca00231340ad3e3b | third party advisory patch |