Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an administrator account via admin/user/add, as demonstrated by a Python PoC script.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-08-06T16:34:23

Updated: 2024-08-05T00:12:43.418Z

Reserved: 2019-07-28T00:00:00

Link: CVE-2019-14347

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-08-06T17:15:43.900

Modified: 2023-03-03T18:41:49.873

Link: CVE-2019-14347

cve-icon Redhat

No data.