Impact
Silverpeas Core versions up to 6.4.6 contain a flaw in the CKEditor image upload component that allows a malicious actor to inject and execute arbitrary JavaScript. The vulnerability is manifested when an image is uploaded via the wysiwyg editor; the image data is not properly sanitized, enabling stored XSS payloads to run in any client that opens the edited content. Successful exploitation could let an attacker steal session cookies, deface web pages, or lift privilege within the user’s browser context.
Affected Systems
The flaw affects the Silverpeas Core product for all versions 6.4.6 and earlier. No specific build numbers or patch information is provided beyond the version cutoff. Users running a Silverpeas Core instance should examine their installed version to determine if it falls within the affected range.
Risk and Exploitability
The CVSS score is 6.1 and the EPSS value is < 1%, indicating a moderate exploitation probability. The vulnerability has not yet been catalogued in the CISA KEV list, indicating no publicly documented, widely used exploitation. Nevertheless, XSS flaws of this nature were historically leveraged by attackers to gain persistent footholds in web applications. Given the lack of a specialized vendor remediating patch in the snippet, the assessment leans toward a moderate to high risk for environments that allow unsanitized image uploads.
OpenCVE Enrichment