An issue exists in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user.
onethink onethink 1.1