Description
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.
Remediation
References
http://silverpeas.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47322
Related Vulnerabilities
CVE-2022-31108 Vulnerability in npm package mermaid
CVE-2021-41269 Vulnerability in maven package com.cronutils:cron-utils
CVE-2019-5480 Vulnerability in npm package statichttpserver
CVE-2018-20227 Vulnerability in maven package org.eclipse.rdf4j:rdf4j-util
CVE-2022-41932 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore