Unpatched Security Flaws Disclosed in Multiple Document Management Systems

A typical attack pattern would be to steal the session cookie that a locally logged in administrator is authenticated with, and reuse that session cookie to impersonate that user to create a new privileged account.

>>More