Greencms · Greencms · CVE-2018-11671
**Name of the Vulnerable Software and Affected Versions**
GreenCMS version 2.3.0603
**Description**
An issue was discovered that allows for a CSRF vulnerability, enabling the addition of an admin account via the "index.php?m=admin&c=access&a=adduserhandle" endpoint.
**Recommendations**
For GreenCMS version 2.3.0603, as a temporary workaround, consider restricting access to the `adduserhandle` action in the `access` controller to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.