Junglewise Threat Intelligence

CVE-2018-3758: express-cart unrestricted file upload vulnerability

CVE-2018-3758 · Severity: low · CVSS 3 · Published 2022-05-13

Technologies: Mrvautin Express-Cart. Vendors: npm.

Executive brief

express-cart is a popular Node.js e-commerce shopping cart module used by online retailers. An attacker with privileged user access (such as a compromised admin account) can upload arbitrary files to the hosting machine, potentially achieving remote code execution and taking complete control of the server infrastructure.

Technical details

This is an unrestricted file upload vulnerability (CWE-434) in express-cart versions before 1.1.7. The file upload functionality lacks proper validation or restrictions on file types and content, allowing an authenticated user with administrative privileges to upload and execute arbitrary files on the server. The attack requires prior authentication with elevated privileges, but once exploited, an attacker gains remote code execution on the hosting machine. The vulnerability was fixed in version 1.1.7 with added limitations to file uploads as shown in the commit adding validation controls to the admin file upload routes.

Affected products

  • mrvautin express-cart before 1.1.7

Timeline

  • 2018-06-07: disclosed: Published on NVD
  • 2022-05-13: patched: Advisory published; fix available in version 1.1.7

References

Related threats