Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection.
https://yuyudhn.github.io/CVE-2022-46074/
https://www.youtube.com/watch?v=5Q3vyTo02bc&ab_channel=IkariShinji