CVE-2018-12457

Publication date

2018-06-15 14:00:00

Family

mitre

State

PUBLISHED

Description

expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.