Yes!
I tried and actually
can use each Admin username to login the AdminCP without any password.
Checked the $bbuserinfo and it's always me (guess from cookie infos..), but the login name can be anyone of the other admins.
Could you explain me why ????
Thanks
P.S.: just a point out. I can use
ANY loginusername=dummy to directly enter the AdminCP, bypassing the login challenge page... Neither is needed an actual bb username. Very very unpredictable...
Sessions.... bah!!!

aranoid:
It seems unsafe, first touch... but cookies are the network security atom .... :knockedout: