Critical Vulnerability Information Vulnerability Description CVE ID: CVE-2025-44186 Vulnerability Type: Cross-Site Request Forgery (CSRF) Affected Component: /admin/Operation/User.php Attack Type: Local Impact: - Code Execution: ✅ - Privilege Escalation: ✅ Attack Vector By tricking an authenticated administrator into visiting a malicious website, an attacker can perform a CSRF attack, silently submitting a POST request to the vulnerable endpoint, resulting in the creation of a new user. CSRF Payload (Malicious HTML Form)