Description
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
Remediation
References
https://hackerone.com/reports/343626
Related Vulnerabilities
CVE-2021-34080 Vulnerability in npm package ssl-utils
CVE-2018-3721 Vulnerability in maven package org.webjars.npm:lodash.merge
CVE-2019-6286 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http2:http2-hpack
CVE-2022-45146 Vulnerability in maven package org.bouncycastle:bc-fips