
Nixon-H/Unauthenticated-Admin-Account-Creation
Releases0
Stars1
Description: A Critical (9.8) vulnerability where administrative backend scripts lack session validation. Unauthenticated attackers can send direct POST requests to create new "Active" seller or user accounts, bypassing the admin dashboard login and all registration approval workflows.