Record summary

CVE-2023-47321 has a selected CVSS score of 4.9 (medium); EIP currently links 1 curated repository PoC.

Description

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 26, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

org.silverpeas.core:silverpeas-core-web

Browse Maven / org.silverpeas.core:silverpeas-core-web
GitHub AdvisoryBefore 6.3.2 · Fixed in 6.3.2affected

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2023-47321Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file

Python · 848 B · linked to 2 vulnerabilities

GitHub

PoC details

References

4