Executive brief
express-cart is a Node.js e-commerce shopping cart application. The vulnerability allows unauthenticated attackers to perform unauthorized administrative actions (such as creating discount codes) by tricking a logged-in admin into visiting a malicious website. An attacker can modify store settings, create fake discounts, or alter product data without the admin's knowledge.
Technical details
The vulnerability is a Cross-Site Request Forgery (CSRF) vulnerability in express-cart versions up to 1.1.10. The root cause is that the admin API endpoints only validate session cookies without implementing CSRF tokens, allowing an attacker to craft a malicious HTML form that, when visited by an authenticated admin, performs unwanted state-changing actions. The attack vector is network-based and requires user interaction (the admin must visit the attacker's page while logged into express-cart). An attacker can exploit this to create discount codes, modify settings, or perform other admin-level operations. The vulnerability was fixed in version 1.1.17.
Affected products
- express-cart express-cart through 1.1.10
Timeline
- 2020-02-22: disclosed
- 2021-08-30: advisory
- 2021: patched: Fixed in version 1.1.17