CVE-2023-47320
HIGH
Broken access control in Silverpeas
Record summary
CVE-2023-47320 has a selected CVSS score of 8.1 (high); EIP currently links 8 curated repository PoCs.
Description
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 8
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
org.silverpeas.core:silverpeas-core-warBrowse Maven / org.silverpeas.core:silverpeas-core-war | GitHub Advisory | Before 6.3.2 · Fixed in 6.3.2 | affected |
org.silverpeas.core:silverpeas-core-webBrowse Maven / org.silverpeas.core:silverpeas-core-web | GitHub Advisory | Before 6.3.2 · Fixed in 6.3.2 | affected |
Proofs of concept
8Curated repository PoCs
GitHubCVE-2023-47320Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file
GitHubCVE-2023-47327Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file
GitHubCVE-2023-47325Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file
GitHubCVE-2023-47321Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file
GitHubCVE-2023-47326Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed2 files
GitHubCVE-2023-47324Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file
GitHubCVE-2023-47323Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file
GitHubCVE-2023-47322Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed2 files
References
5silverpeas.com
http://silverpeas.com/ github.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47320 github.com
https://github.com/Silverpeas/Silverpeas-Core github.com
https://github.com/Silverpeas/Silverpeas-Core/commit/fcb4a9740b6c80859e435045b549290a82ae84a2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-47320