Description
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
Remediation
References
http://silverpeas.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47325
Related Vulnerabilities
CVE-2023-34093 Vulnerability in npm package @strapi/strapi
CVE-2022-31129 Vulnerability in maven package org.webjars.bowergithub.moment:moment
CVE-2020-7638 Vulnerability in npm package confinit
CVE-2022-24728 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2018-12542 Vulnerability in maven package io.vertx:vertx-web