Vulnerability Description
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silverpeas | Silverpeas | < 6.3.2 |
Related Weaknesses (CWE)
References
- http://silverpeas.comProduct
- https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47325ExploitThird Party Advisory
- http://silverpeas.comProduct
- https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47325ExploitThird Party Advisory
FAQ
What is CVE-2023-47325?
CVE-2023-47325 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can ...
How severe is CVE-2023-47325?
CVE-2023-47325 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-47325?
Check the references section above for vendor advisories and patch information. Affected products include: Silverpeas Silverpeas.