Description
UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific parameters to generate a new admin user with full system access.
Problem types
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51433
www.exploit-db.com/exploits/51433 (ExploitDB-51433)
web.archive.org/web/20230314183734/https://en.ulicms.de/ (Archived Product Webpage)
www.vulncheck.com/...-unauthenticated-admin-account-creation (VulnCheck Advisory: UliCMS 2023.1 Privilege Escalation via Unauthenticated Admin Account Creation)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.