pages/register/register.php in Fishyshoop 0.930 beta allows remote attackers to create arbitrary administrative users by setting the is_admin HTTP POST parameter to 1.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fishyshoop | Fishyshoop | 0.930_beta (including) | 0.930_beta (including) |