Description
Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

Silverpeas Core 6.4.6 suffers a cross‑site scripting flaw that allows an attacker to upload files through the document management feature that contain malicious scripts. When an authenticated user views or downloads such a file, the embedded script can execute in that user's browser context, potentially leading to session hijacking, credential theft, or defacement of content. The weakness originates from insufficient sanitization or validation of uploaded file content or metadata, a typical injection vulnerability. The CVE description explicitly states that the script executes when an authenticated user views or downloads the file, indicating that the victim must be logged in to trigger the script.

Affected Systems

Silverpeas Core version 6.4.6 is affected. No other product versions are listed in the available data.

Risk and Exploitability

The vulnerability is a client‑side XSS that generally requires the victim to load or interact with the malicious file. Because the attack depends on user actions and does not involve remote code execution on the server, the overall exploitation complexity is moderate. The EPSS score is <1% and the issue is not listed in the CISA KEV catalog, indicating limited publicly known exploitation activity. The CVSS score is 6.1, reflecting moderate severity. The CVE description explicitly states that execution occurs when an authenticated user views or downloads the file, confirming that the attack vector relies on an authenticated user interacting with the file.

Generated by OpenCVE AI on September 10, 2026 at 04:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Silverpeas Core to a version where the file‑upload XSS issue is fixed.
  • If an update is not yet available, enforce strict file‑type restrictions and sanitize uploaded file names and content before storage or rendering.
  • Configure the web server to apply strict content‑type headers and escape any residual script content in served pages.
  • Regularly monitor for suspicious client‑side script activity and validate that sanitization policies remain effective.

Generated by OpenCVE AI on September 10, 2026 at 04:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via File Upload in Silverpeas Core 6.4.6

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T20:07:09.410Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-78738

cve-icon Vulnrichment

Updated: 2026-09-09T18:38:51.733Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T21:18:41.797

Modified: 2026-09-09T20:20:42.227

Link: CVE-2026-78738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')