Record summary

CVE-2023-47327 has a selected CVSS score of 4.3 (medium); EIP currently links 1 curated repository PoC.

Description

The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 26, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

org.silverpeas.core:silverpeas-core-web

Browse Maven / org.silverpeas.core:silverpeas-core-web
GitHub AdvisoryBefore 6.3.2 · Fixed in 6.3.2affected

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2023-47327Curated repository PoCby RhinoSecurityLabsStars: 905Not analyzed1 file

Python · 1.2 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

4