Impact
Silverpeas Core versions 6.4.6 and earlier are affected by a cross‑site scripting vulnerability that can be triggered through the Multimedia library application. The flaw permits arbitrary script injection via the multimedia functionality. Typical XSS impacts such as defacement or data theft could result, inferred from the nature of the flaw.
Affected Systems
Silverpeas Core up to and including version 6.4.6 is affected. No other vendor or product information is listed in the advisory.
Risk and Exploitability
The vulnerability is not listed in the CISA KEV catalog and the EPSS score is <1%, indicating a low but non‑zero exploitation probability. The CVSS score of 6.1 denotes moderate severity. The precise attack vector is not detailed in the advisory, so the risk profile will depend on how the multimedia library might be exposed; typical XSS requires some form of user supplied data. Consequently, the risk is moderate; organizations should monitor for attempts to inject scripts via the multimedia upload paths and apply mitigations as soon as a vendor patch is available.
OpenCVE Enrichment