info: name: EasyCVR Arbitrary User Addition author: ProjectDiscoveryAI,dostghost severity: critical description: | EasyCVR video management platform allows arbitrary user addition through an unprotected endpoint. Exploiting this, an attacker can add a new administrator user. reference: - https://github.com/AboSteam/POPC/blob/main/EasyCVR%E8%A7%86%E9%A2%91%E7%AE%A1%E7%90%86%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E6%B7%BB%E5%8A%A0%E6%BC%8F%E6%B4%9E.md metadata: fofa-query: app="EasyCVR-视频管理平台" tags: easycvr, adduser, critical