Privilege Escalation in express-cart
Critical severity
GitHub Reviewed
Published
Jun 3, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 3, 2019
Published to the GitHub Advisory Database
Jun 3, 2019
Last updated
Jan 9, 2023
Versions of
express-cart
before 1.1.6 are vulnerable to privilege escalation. This vulnerability can be exploited so that normal users can escalate their privilege and add new administrator users.Recommendation
Update to version 1.1.6 or later.
References