Description
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
Remediation
References
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47320
Related Vulnerabilities
CVE-2016-0709 Vulnerability in maven package org.apache.portals.jetspeed-2:j2-admin
CVE-2023-3431 Vulnerability in maven package net.sourceforge.plantuml:plantuml
CVE-2021-30246 Vulnerability in npm package jsrsasign
CVE-2018-20677 Vulnerability in npm package bootstrap-sass
CVE-2022-31129 Vulnerability in maven package org.webjars.bower:moment