Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3fc5-9x9m-vqc4

Опубликовано: 03 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Duplicate Advisory: Privilege Escalation in express-cart

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-hr89-w7p6-pjmq. This link is maintained to preserve external references.

Original Description

Versions of express-cart before 1.1.6 are vulnerable to privilege escalation. This vulnerability can be exploited so that normal users can escalate their privilege and add new administrator users.

Recommendation

Update to version 1.1.6 or later.

Пакеты

Наименование

express-cart

npm
Затронутые версииВерсия исправления

< 1.1.6

1.1.6

9.8 Critical

CVSS3

9.8 Critical

CVSS3