A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.
- https://blog.csdn.net/sugaryzheng/article/details/133283101?spm=1001.2014.3001.5501
No PoCs found on GitHub currently.