Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| express-cart(npm) | 0 | 1.1.17 | N/A |
CVSS Metrics