icon

We found results for “

WS-2020-0427

Good to know:

icon

Date: February 12, 2020

In express-cart in versions 1.0.1 to 1.1.16 is vulnerable to CSRF. It allows attacker cheat admin to do bad behaviors . Main reason is csrf token isn't used

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Cross-Site Request Forgery (CSRF)

CWE-352

Top Fix

icon

Upgrade Version

Upgrade to version express-cart - 1.1.17

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us