Eventum · Eventum · CVE-2018-12628
**Name of the Vulnerable Software and Affected Versions**
Eventum version 3.5.0
**Description**
An issue was discovered that allows CSRF in the htdocs/manage/users.php file, enabling the creation of another user with admin privileges.
**Recommendations**
For Eventum version 3.5.0, update to a newer version that contains a fix for this issue, or as a temporary workaround, consider restricting access to the htdocs/manage/users.php file to minimize the risk of exploitation.