Description
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
Affected products
- HackerOne / express-cart>=1.1.6 – >=1.1.6
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.