Filtered by vendor Express-cart Project
Subscriptions
Filtered by product Express-cart
Subscriptions
Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-32573 | 1 Express-cart Project | 1 Express-cart | 2024-11-21 | 4.8 Medium |
The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website. | ||||
CVE-2020-22403 | 1 Express-cart Project | 1 Express-cart | 2024-11-21 | 8.8 High |
Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts. | ||||
CVE-2018-3758 | 1 Express-cart Project | 1 Express-cart | 2024-11-21 | 8.8 High |
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine. | ||||
CVE-2018-16483 | 1 Express-cart Project | 1 Express-cart | 2024-11-21 | N/A |
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators. |
Page 1 of 1.