Broken Access Control in Silverpeas Core Affects User Privileges
CVE-2023-47325

5.4MEDIUM

Key Information:

Vendor
Silverpeas
Vendor
CVE Published:
13 December 2023

Summary

The Silverpeas Core 6.3.1 is vulnerable to a broken access control issue affecting the administrative 'Bin' feature. A malicious user with insufficient privileges can gain unauthorized access to deleted spaces by navigating directly to the bin. This allows them to view, restore, or permanently delete these spaces, leading to potential data loss and unauthorized information exposure.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-47325 : Broken Access Control in Silverpeas Core Affects User Privileges | SecurityVulnerability.io