Description
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
Remediation
References
http://silverpeas.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47325
Related Vulnerabilities
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:sbt
CVE-2022-0122 Vulnerability in npm package node-forge
CVE-2020-7630 Vulnerability in npm package git-add-remote
CVE-2021-34371 Vulnerability in maven package org.neo4j:neo4j
CVE-2023-26480 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livedata-webjar