BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI.
- https://github.com/source-trace/beescms/issues/4
No PoCs found on GitHub currently.