Description
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
Remediation
References
http://silverpeas.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47320
Related Vulnerabilities
CVE-2022-25878 Vulnerability in maven package org.webjars.npm:protobufjs
CVE-2018-6561 Vulnerability in maven package org.webjars.npm:dijit
CVE-2023-30527 Vulnerability in maven package org.jenkins-ci.plugins:wso2id-oauth
CVE-2022-25766 Vulnerability in npm package ungit
CVE-2020-21122 Vulnerability in maven package com.bstek.ureport:ureport2-console