### [CVE-2018-16483](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16483) ![](https://img.shields.io/static/v1?label=Product&message=express-cart&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Privilege%20Escalation%20(CAPEC-233)&color=brighgreen) ### Description A deficiency in the access control in module express-cart <=1.1.5 allows unprivileged users to add new users to the application as administrators. ### POC #### Reference - https://hackerone.com/reports/343626 - https://hackerone.com/reports/343626 #### Github No PoCs found on GitHub currently.