Insufficient input validation of the plugin parameter of the create_user plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
plugin
create_user