← Back

Express Cart

express-cart

Vendor: Express Cart Project • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Express Cart Project
1Express Cart
Nov 21, 2024
Aug 12, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts.
1Express Cart Project
1Express Cart
Nov 21, 2024
May 11, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website.
1Express Cart Project
1Express Cart
Nov 21, 2024
Feb 1, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
1Express Cart Project
1Express Cart
Nov 21, 2024
Jun 7, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.