CVE-2018-16483
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators.
Affected products
HackerOne · express-cartReferences
https://hackerone.com/reports/343626