Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter set to 1.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Zomplog | Zomp | * | 3.8.2 (including) |