CyberRota Analysis
AI-GeneratedA low-privileged remote attacker with a valid session can exploit a vulnerability in the user creation functionality of the affected application to create new accounts with arbitrary roles, potentially granting themselves the highest privileges. This could lead to unauthorized access and control over sensitive data and functionalities. Organizations using this application should prioritize patching this vulnerability to mitigate the risk of privilege escalation and unauthorized account creation.
Original NVD Description
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.