An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add.
- https://github.com/jbroadway/elefant/issues/285
No PoCs found on GitHub currently.