Description
UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.
Problem types
Authorization Bypass Through User-Controlled Key
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51486
www.exploit-db.com/exploits/51486 (ExploitDB-51486)
web.archive.org/web/20230314183734/https://en.ulicms.de/ (Archived Product Webpage)
www.vulncheck.com/...ypass-via-mass-assignment-vulnerability (VulnCheck Advisory: UliCMS 2023.1 Authentication Bypass via Mass Assignment Vulnerability)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.