Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zomplog | Zomp | * | 3.8.2 (including) |