CVE-2018-3758
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 27%
exploitation probability
27%top 2% of all CVEs
observed exploitation
nono source reports it
Unrestricted file upload (RCE) in express-cart module before 1.1.7 allows a privileged user to gain access in the hosting machine.
Affected products
HackerOne · express-cartReferences
https://hackerone.com/reports/343726