xyhai.php?s=/Auth/addUser in XYHCMS 3.5 allows CSRF to add a background administrator account.Referenceshttps://github.com/maoGod/xyhcms/issues/1