A cross-site request forgery (CSRF) in OPMS v1.3 and below allows attackers to arbitrarily add a user account via /user/add.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20595
Reference (s):
- https://github.com/lock-upme/OPMS/issues/25