Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-42g3-3jwm-63rx | Broken access control in Silverpeas |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 22 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-22T18:23:42.028Z
Reserved: 2023-11-06T00:00:00.000Z
Link: CVE-2023-47325
Updated: 2024-08-02T21:09:36.667Z
Status : Modified
Published: 2023-12-13T14:15:44.390
Modified: 2025-05-22T19:15:36.867
Link: CVE-2023-47325
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA