Description
The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.
Remediation
References
http://silverpeas.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47327
Related Vulnerabilities
CVE-2021-21321 Vulnerability in npm package fastify-reply-from
CVE-2022-38752 Vulnerability in maven package org.yaml:snakeyaml
CVE-2021-32621 Vulnerability in maven package org.xwiki.platform:xwiki-platform-dashboard-macro
CVE-2018-16459 Vulnerability in npm package exceljs
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_2.13