Record summary

CVE-2023-47325 has a selected CVSS score of 5.4 (medium); EIP currently links 1 curated repository PoC.

Description

Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 22, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

org.silverpeas.core:silverpeas-core-web

Browse Maven / org.silverpeas.core:silverpeas-core-web
GitHub AdvisoryBefore 6.3.2 · Fixed in 6.3.2affected

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2023-47325Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file

Python · 1.1 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

4