Description
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
Remediation
References
https://hackerone.com/reports/343726
Related Vulnerabilities
CVE-2023-29516 Vulnerability in maven package org.xwiki.platform:xwiki-platform-attachment-ui
CVE-2017-16026 Vulnerability in maven package org.webjars.npm:request
CVE-2020-36649 Vulnerability in maven package org.webjars.npm:papaparse
CVE-2017-9805 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2022-22963 Vulnerability in maven package org.springframework.cloud:spring-cloud-function-core