Security Advisory

CVE-2023-53914

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-17 22:44:49
Last updated 2026-04-07 14:07:35
Assigner VulnCheck
State PUBLISHED

Description

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.