The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-12-13T00:00:00
Updated: 2024-08-02T21:09:36.054Z
Reserved: 2023-11-06T00:00:00
Link: CVE-2023-47322
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-13T14:15:44.247
Modified: 2024-11-21T08:30:09.447
Link: CVE-2023-47322
Redhat
No data.