
This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by using any incorrect password in a Basic Authentication header. Attackers could abuse this flaw to create a new administrator account without prior authentication.
이 취약점을 통해 유효한 관리자 사용자 이름을 아는 인증되지 않은 공격자는 Basic Authentication 헤더에 잘못된 비밀번호를 사용하여 REST API 요청 중 해당 관리자를 가장할 수 있습니다. 공격자는 이 결함을 악용하여 사전 인증 없이 새 관리자 계정을 생성할 수 있습니다.
