NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain privileged access.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon