ZeroHour

CVE-2020-22403

CVSS 3.1
8.8 high
EPSS
<1%p45
Published
()
Modified
Description

Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other unspecified impacts.

Vendors
express-cart project
Products
express-cart
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.