An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.
- https://github.com/hiliqi/xiaohuanxiong/issues/28
No PoCs found on GitHub currently.