CVE-2023-47325
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Dec 13, 2023
Updated: Dec 18, 2023
Summary
CVE-2023-47325 is a vulnerability affecting Silverpeas Core 6.3.1. This issue involves a broken access control in the administrative "Bin" feature. A user with lower privileges can bypass restrictions and directly access the bin, gaining unauthorized access to information about all deleted spaces. The user can then choose to restore or permanently delete these spaces, resulting in potential data loss or unintended modifications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share