CVE-2023-47322
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.
- Affected products
- Silverpeas Core
- Silverpeas
- < 6.3.2
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.4% (32th percentile)
- Weakness
- CWE-352
- NVD status
- Modified
- Published
- 2023-12-13
CVE-2023-47322 at NVD
1 known exploit for CVE-2023-47322
Proof-of-concept code and exploit modules indexed by Sploitus