Cross-site Scripting in express-cart
Moderate severity
Unreviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 11, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Feb 1, 2023
The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website."
References