Cross-site request forgery (CSRF) vulnerability in admin/admin_options.php in VR GPub 4.0 allows remote attackers to hijack the authentication of admins for requests that add admin accounts via an add action.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/72745http://www.exploit-db.com/exploits/18418http://secunia.com/advisories/47729