Showing 2 vulnerabilities on this page for express-cart

Signals CISA KEV Ransomware Nuclei
HackerOne vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Authentication Bypass by Spoofing in express-cart

A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.

CWE-290Feb 1, 2019
CVSS8.8v3.0EPSS1.16%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

express-cart unrestricted file upload vulnerability

Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.

CWE-22CWE-434Jun 7, 2018
CVSS8.8v3.1EPSS27.5%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX