main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.083
EPSS Ranking 91.9%