Executive brief
express-cart is an open-source e-commerce shopping cart platform. A security flaw allows any user to bypass access controls and create new administrator accounts. This could lead to a complete takeover of the online store, allowing unauthorized individuals to access customer data, modify orders, or disrupt business operations.
Technical details
A privilege escalation vulnerability exists in express-cart versions prior to 1.1.6 due to insufficient access control checks during user creation. An attacker can exploit this by sending a crafted request to the user registration or management endpoints, potentially by manipulating the referrer or other request parameters to bypass authorization logic. Successful exploitation allows a remote attacker to create a new user with administrative privileges. This results in a complete compromise of the application's integrity and confidentiality. The issue was addressed in version 1.1.6 by improving the validation of administrative user creation.
Affected products
- mrvautin express-cart < 1.1.6
Timeline
- 2018-07-12: disclosed: Vulnerability disclosed via HackerOne report 343626
- 2019-06-03: advisory: GitHub Advisory published
- 2026-02-03: other: Advisory withdrawn as a duplicate of GHSA-hr89-w7p6-pjmq