Impact
Silverpeas Core 6.4.6 suffers a cross‑site scripting flaw that allows an attacker to upload files through the document management feature that contain malicious scripts. When an authenticated user views or downloads such a file, the embedded script can execute in that user's browser context, potentially leading to session hijacking, credential theft, or defacement of content. The weakness originates from insufficient sanitization or validation of uploaded file content or metadata, a typical injection vulnerability. The CVE description explicitly states that the script executes when an authenticated user views or downloads the file, indicating that the victim must be logged in to trigger the script.
Affected Systems
Silverpeas Core version 6.4.6 is affected. No other product versions are listed in the available data.
Risk and Exploitability
The vulnerability is a client‑side XSS that generally requires the victim to load or interact with the malicious file. Because the attack depends on user actions and does not involve remote code execution on the server, the overall exploitation complexity is moderate. The EPSS score is <1% and the issue is not listed in the CISA KEV catalog, indicating limited publicly known exploitation activity. The CVSS score is 6.1, reflecting moderate severity. The CVE description explicitly states that execution occurs when an authenticated user views or downloads the file, confirming that the attack vector relies on an authenticated user interacting with the file.
OpenCVE Enrichment