Executive brief
express-cart is a popular Node.js e-commerce shopping cart module used by online retailers. An attacker with privileged user access (such as a compromised admin account) can upload arbitrary files to the hosting machine, potentially achieving remote code execution and taking complete control of the server infrastructure.
Technical details
This is an unrestricted file upload vulnerability (CWE-434) in express-cart versions before 1.1.7. The file upload functionality lacks proper validation or restrictions on file types and content, allowing an authenticated user with administrative privileges to upload and execute arbitrary files on the server. The attack requires prior authentication with elevated privileges, but once exploited, an attacker gains remote code execution on the hosting machine. The vulnerability was fixed in version 1.1.7 with added limitations to file uploads as shown in the commit adding validation controls to the admin file upload routes.
Affected products
- mrvautin express-cart before 1.1.7
Timeline
- 2018-06-07: disclosed: Published on NVD
- 2022-05-13: patched: Advisory published; fix available in version 1.1.7