{"id":"CVE-2018-12457","aliases":["GHSA-hr89-w7p6-pjmq"],"url":"https://o3.security/vulnerability/CVE-2018-12457","summary":"express-cart allows any user to create an admin user","details":"expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.","published":"2018-06-15T14:29:00.227Z","modified":"2026-03-14T09:27:23.207494Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"express-cart","fixedVersion":"1.1.6"}],"fix":{"url":"https://github.com/mrvautin/expressCart/commit/baccaae9b0b72f00b10c5453ca00231340ad3e3b","label":"mrvautin/expressCart@baccaae"},"references":[{"type":"ADVISORY","url":"https://www.npmjs.com/package/express-cart?activeTab=versions"},{"type":"REPORT","url":"https://hackerone.com/reports/343626"},{"type":"FIX","url":"https://github.com/mrvautin/expressCart/commit/baccaae9b0b72f00b10c5453ca00231340ad3e3b"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12457"},{"type":"PACKAGE","url":"https://github.com/mrvautin/expressCart"},{"type":"WEB","url":"https://github.com/nodejs/security-wg/blob/main/vuln/npm/469.json"},{"type":"WEB","url":"https://snyk.io/vuln/npm:express-cart:20180712"},{"type":"WEB","url":"https://www.npmjs.com/advisories/730"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-14T09:27:23.207494Z"}}