The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-13T00:00:00

Updated: 2024-08-02T21:09:36.054Z

Reserved: 2023-11-06T00:00:00

Link: CVE-2023-47322

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-13T14:15:44.247

Modified: 2023-12-15T21:08:27.877

Link: CVE-2023-47322

cve-icon Redhat

No data.