Description
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
Remediation
References
https://hackerone.com/reports/343726
Related Vulnerabilities
CVE-2023-45279 Vulnerability in maven package org.yamcs:yamcs-core
CVE-2021-23567 Vulnerability in npm package colors
CVE-2022-23463 Vulnerability in maven package com.nepxion:discovery-commons
CVE-2018-3724 Vulnerability in npm package general-file-server
CVE-2021-25329 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core