A CSRF Issue that can add an admin user exists in UKcms v1.1.10 via admin.php/admin/role/add.html.
ukcms ukcms 1.1.10