This advisory has been withdrawn because it is a duplicate of GHSA-hr89-w7p6-pjmq. This link is maintained to preserve external references.
Versions of express-cart before 1.1.6 are vulnerable to privilege escalation. This vulnerability can be exploited so that normal users can escalate their privilege and add new administrator users.
Update to version 1.1.6 or later.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2019-06-03T17:30:55Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}