A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Express-cart | Express-cart_project | * | 1.1.5 (including) |