Junglewise Threat Intelligence

CVE-2020-22403: express-cart Cross-Site Request Forgery in admin

CVE-2020-22403 · Severity: low · CVSS 3.1 · Published 2021-08-30

Technologies: express-cart (npm). Vendors: npm.

Executive brief

express-cart is a Node.js e-commerce shopping cart application. The vulnerability allows unauthenticated attackers to perform unauthorized administrative actions (such as creating discount codes) by tricking a logged-in admin into visiting a malicious website. An attacker can modify store settings, create fake discounts, or alter product data without the admin's knowledge.

Technical details

The vulnerability is a Cross-Site Request Forgery (CSRF) vulnerability in express-cart versions up to 1.1.10. The root cause is that the admin API endpoints only validate session cookies without implementing CSRF tokens, allowing an attacker to craft a malicious HTML form that, when visited by an authenticated admin, performs unwanted state-changing actions. The attack vector is network-based and requires user interaction (the admin must visit the attacker's page while logged into express-cart). An attacker can exploit this to create discount codes, modify settings, or perform other admin-level operations. The vulnerability was fixed in version 1.1.17.

Affected products

  • express-cart express-cart through 1.1.10

Timeline

  • 2020-02-22: disclosed
  • 2021-08-30: advisory
  • 2021: patched: Fixed in version 1.1.17

References

Related threats