Loading HuntDB...

GHSA-wj36-v8j4-pc7c

GitHub Security Advisory

Authentication Bypass by Spoofing in express-cart

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.

Affected Packages

npm express-cart
Affected versions: 0 (fixed in 1.1.6)

Related CVEs

Key Information

GHSA ID
GHSA-wj36-v8j4-pc7c
Published
February 7, 2019 6:16 PM
Last Modified
September 14, 2022 10:42 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
express-cart
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 1, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.