Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-47323


The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.


Published

2023-12-13T14:15:44.293

Last Modified

2024-11-21T08:30:09.590

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application silverpeas silverpeas < 6.3.2 Yes

References