Medium severity4.8NVD Advisory· Published May 11, 2021· Updated Jun 17, 2026
CVE-2021-32573
CVE-2021-32573
Description
The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for product options. NOTE: the vendor states that this "would rely on an admin hacking his/her own website.
Affected products
3- cpe:2.3:a:express-cart_project:express-cart:*:*:*:*:*:node.js:*:*Range: <=1.1.10
- express-cart/express-cartdescription
- Range: <=1.1.10
Patches
Vulnerability mechanics
References
1- hackerone.com/reports/395944nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.