CVE-2023-47325
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
- Affected products
- Silverpeas Core
- Silverpeas
- < 6.3.2
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.4% (34th percentile)
- Weakness
- CWE-284
- NVD status
- Modified
- Published
- 2023-12-13
CVE-2023-47325 at NVD
1 known exploit for CVE-2023-47325
Proof-of-concept code and exploit modules indexed by Sploitus