expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.
References
Link | Resource |
---|---|
https://www.npmjs.com/package/express-cart?activeTab=versions | Third Party Advisory |
https://hackerone.com/reports/343626 | Issue Tracking Third Party Advisory |
https://github.com/mrvautin/expressCart/commit/baccaae9b0b72f00b10c5453ca00231340ad3e3b | Patch Third Party Advisory |
Configurations
Information
Published : 2018-06-15 07:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-12457
Mitre link : CVE-2018-12457
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
expresscart_project
- expresscart