Junglewise Threat Intelligence

mrvautin express-cart privilege escalation

Severity: low · CVSS 3.1 · Published 2019-06-03

Technologies: Mrvautin Express-Cart. Vendors: npm.

Executive brief

express-cart is an open-source e-commerce shopping cart platform. A security flaw allows any user to bypass access controls and create new administrator accounts. This could lead to a complete takeover of the online store, allowing unauthorized individuals to access customer data, modify orders, or disrupt business operations.

Technical details

A privilege escalation vulnerability exists in express-cart versions prior to 1.1.6 due to insufficient access control checks during user creation. An attacker can exploit this by sending a crafted request to the user registration or management endpoints, potentially by manipulating the referrer or other request parameters to bypass authorization logic. Successful exploitation allows a remote attacker to create a new user with administrative privileges. This results in a complete compromise of the application's integrity and confidentiality. The issue was addressed in version 1.1.6 by improving the validation of administrative user creation.

Affected products

  • mrvautin express-cart < 1.1.6

Timeline

  • 2018-07-12: disclosed: Vulnerability disclosed via HackerOne report 343626
  • 2019-06-03: advisory: GitHub Advisory published
  • 2026-02-03: other: Advisory withdrawn as a duplicate of GHSA-hr89-w7p6-pjmq

References

Related threats