An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/wu610777031/My_CMSHunter