← Back to CVE List

CVE-2021-32573

Published: 2021-05-11T17:15Z
Last Modified: 2024-11-21T06:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt