Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
References
Link | Resource |
---|---|
https://hackerone.com/reports/343726 | Exploit Patch Third Party Advisory |
Configurations
Information
Published : 2018-06-07 14:29
Updated : 2023-01-30 08:05
NVD link : CVE-2018-3758
Mitre link : CVE-2018-3758
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
express-cart_project
- express-cart