vendor:
Crypto Currency Tracker
by:
0xBr
9,8
CVSS
CRITICAL
Admin Account Creation
798
CWE
Product Name: Crypto Currency Tracker
Affected Version From: <=9.5
Affected Version To: 9.5
Patch Exists: NO
Related CWE: CVE-2023-37759
CPE: a:crypto_currency_tracker:crypto_currency_tracker:9.5
Platforms Tested:
2023
Crypto Currency Tracker (CCT) 9.5 – Admin Account Creation (Unauthenticated)
This exploit allows an unauthenticated user to create an admin account in Crypto Currency Tracker (CCT) version 9.5. By sending a POST request to the /en/user/register endpoint with the required parameters, the attacker can create a new admin account without proper authentication.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Crypto Currency Tracker (CCT) that fixes this issue.