CVE-2023-47323
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 13, 2023
Updated: Dec 15, 2023
Summary
CVE-2023-47323 is a vulnerability affecting the notification/messaging feature in Silverpeas Core 6.3.1. The issue resides in a lack of access control enforcement on the ID parameter. An attacker can exploit this vulnerability to read all messages exchanged between users, even those intended for administrators only. This poses a significant risk to the confidentiality of communication within the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share