Description
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrator, possibly deleting the existing default admin user in the process and allowing a wide variety of impacts.
Remediation
References
Related Vulnerabilities
WordPress Plugin OdiHost Newsletter 'openstat.php' SQL Injection (1.0)
WordPress Plugin WordPress Ultra Simple Paypal Shopping Cart Cross-Site Request Forgery (4.4)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-0304)
WordPress Plugin Profile Builder Pro Security Bypass (3.1.0)