An issue was discovered in JIZHI CMS 1.9.4. There is a CSRF vulnerability that can add an admin account via index, /admin.php/Admin/adminadd.htmlReferenceshttps://gist.github.com/yinfei6/17bbeece7cf5a8f9c31f7a517d85b247