Headline
OpenBMCS 2.4 Create Admin / Remote Privilege Escalation
The application suffers from an insecure permissions and privilege escalation vulnerability. A regular user can create administrative users and/or elevate her privileges by sending an HTTP POST request to specific PHP scripts in ‘/plugins/useradmin/’ directory.