CVE-2023-47320
EPSS 0.27%Broken access control in Silverpeas
發布日:2023/12/13修改日:2023/12/13
描述
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
受影響套件(2)
- Maven/org.silverpeas.core:silverpeas-core-warfrom 0, < 6.3.2
- Maven/org.silverpeas.core:silverpeas-core-webfrom 0, < 6.3.2