Due to the lack of multiple input validation errors, an attacker is able to change the password of the administrative user.
The following link will change the password of the administrative account. Changing the options will also allow you to change the name of the admin account: