expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.
References
Link | Resource |
---|---|
https://github.com/mrvautin/expressCart/commit/baccaae9b0b72f00b10c5453ca00231340ad3e3b | Patch Third Party Advisory |
https://hackerone.com/reports/343626 | Issue Tracking Third Party Advisory |
https://www.npmjs.com/package/express-cart?activeTab=versions | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-06-15 14:29
Updated : 2024-02-28 16:25
NVD link : CVE-2018-12457
Mitre link : CVE-2018-12457
CVE.ORG link : CVE-2018-12457
JSON object : View
Products Affected
expresscart_project
- expresscart
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource