Описание
Authentication Bypass by Spoofing in express-cart
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
Пакеты
Наименование
express-cart
npm
Затронутые версииВерсия исправления
< 1.1.6
1.1.6
Связанные уязвимости
CVSS3: 8.8
nvd
около 7 лет назад
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.