Executive brief
express-cart is a Node.js shopping cart application used by e-commerce platforms. A flaw in access controls allows unprivileged users to create new administrator accounts, enabling complete compromise of the application and access to sensitive customer and business data.
Technical details
express-cart versions 1.1.5 and earlier contain an authentication bypass vulnerability (CWE-290: Improper Access Control) in user administration functionality. Unprivileged, authenticated users can create new administrator accounts despite lacking authorization to do so. The vulnerability requires network access and an existing user account, but no special privileges. An attacker can escalate to full administrator access, gaining control over the entire application including customer data, order processing, and configuration. The vulnerability was patched in version 1.1.6.
Affected products
- express-cart express-cart <=1.1.5
Timeline
- 2019-02-07: disclosed
- 1.1.6: patched: Fixed in version 1.1.6