In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
- https://www.exploit-db.com/exploits/44952/
No PoCs found on GitHub currently.