Cross-site request forgery (CSRF) vulnerability in adduser.do in Symantec LiveUpdate Administrator (LUA) prior to 2.3 allows remote malicious users to hijack the authentication of administrators for requests that create new administrative accounts, and possibly have unspecified other impact, via the userRole parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
symantec liveupdate administrator 2.2.2.9 |