expressCart before 1.1.6 allows remote attackers to create an admin user via a /admin/setup Referer header.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-12457.json"