Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

OOP CMS BLOG 1.0: Unauthenticated Users Can Create Admin Accounts

CVE-2018-25200
Summary

An attacker can create admin accounts without a password by submitting a special form to the website. This is a serious security concern because it allows an unauthorized person to gain control over the website. You should update the software to a fixed version to prevent this from happening.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
tomalofficial php_oop_cms_blog 1.0 –
Original title
OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by crafting malicious POST requests. Attackers can ...
Original description
OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by crafting malicious POST requests. Attackers can submit forms to the addUser.php endpoint with parameters including userName, password, email, and role set to administrative privileges to gain unauthorized access.
nvd CVSS3.1 5.3
nvd CVSS4.0 6.9
Vulnerability type
CWE-352 Cross-Site Request Forgery (CSRF)
Published: 6 Mar 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026