Cross-Site Request Forgery in IBM OmniFind Enterprise Edition
CVE-2010-3891
Currently unrated
Summary
A cross-site request forgery (CSRF) vulnerability exists in the administrator interface of IBM OmniFind Enterprise Edition, specifically within the ESAdmin/security.do component. This flaw allows remote attackers to exploit the trust between an authenticated administrator and the web application, enabling them to hijack the administrator's session. An attacker can perform user-relevant actions such as adding new administrative users through the saveNewUser functionality, potentially compromising the entire system's integrity and security.
References
Timeline
Vulnerability published
Vulnerability Reserved