Description
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
Remediation
References
https://hackerone.com/reports/343626
Related Vulnerabilities
CVE-2021-21368 Vulnerability in npm package msgpack5
CVE-2023-26119 Vulnerability in maven package net.sourceforge.htmlunit:htmlunit
CVE-2021-3780 Vulnerability in npm package peertube
CVE-2020-26256 Vulnerability in npm package @fast-csv/parse
CVE-2021-33561 Vulnerability in maven package com.shopizer:shopizer