Record summary

CVE-2023-47323 has a selected CVSS score of 7.5 (high); EIP currently links 1 curated repository PoC.

Description

The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1

Affected products and versions

2
ProductSourceVersion rangeStatus

org.silverpeas.core:silverpeas-core-api

Browse Maven / org.silverpeas.core:silverpeas-core-api
GitHub AdvisoryBefore 6.3.2 · Fixed in 6.3.2affected

org.silverpeas.core:silverpeas-core-web

Browse Maven / org.silverpeas.core:silverpeas-core-web
GitHub AdvisoryBefore 6.3.2 · Fixed in 6.3.2affected

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2023-47323Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file

Python · 1.1 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

5