Broken Access Control in Silverpeas Core Affects User Privileges
CVE-2023-47325
5.4MEDIUM
What is CVE-2023-47325?
The Silverpeas Core 6.3.1 is vulnerable to a broken access control issue affecting the administrative 'Bin' feature. A malicious user with insufficient privileges can gain unauthorized access to deleted spaces by navigating directly to the bin. This allows them to view, restore, or permanently delete these spaces, leading to potential data loss and unauthorized information exposure.