QID 980806
QID 980806: Nodejs (npm) Security Update for express-cart (GHSA-wj36-v8j4-pc7c)
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-wj36-v8j4-pc7c for updates pertaining to this vulnerability.
Vendor References
- GHSA-wj36-v8j4-pc7c -
github.com/advisories/GHSA-wj36-v8j4-pc7c
CVEs related to QID 980806
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wj36-v8j4-pc7c | express-cart |
|