Description
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.
Remediation
References
http://silverpeas.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47321
Related Vulnerabilities
CVE-2023-41037 Vulnerability in maven package org.webjars.bowergithub.openpgpjs:openpgpjs
CVE-2021-21368 Vulnerability in maven package org.webjars.npm:msgpack5
CVE-2022-23458 Vulnerability in maven package org.webjars.bowergithub.nhn:tui.grid
CVE-2022-21830 Vulnerability in npm package @rocket.chat/livechat
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:ua-parser-js