CVE-2023-47320: High severity Silverpeas Silverpeas vulnerability
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-webto a version that resolves this vulnerability.Fixed in 6.3.2 - Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-warto a version that resolves this vulnerability.Fixed in 6.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47320?
The severity of CVE-2023-47320 is classified as high due to the potential for unauthorized access to critical application functionalities.
How do I fix CVE-2023-47320?
To mitigate CVE-2023-47320, upgrade to Silverpeas Core version 6.3.2 or later.
Who is affected by CVE-2023-47320?
CVE-2023-47320 affects all users of Silverpeas Core versions prior to 6.3.2.
What systems are impacted by CVE-2023-47320?
CVE-2023-47320 specifically impacts installations of Silverpeas Core that are running versions up to 6.3.1.
What type of vulnerability is CVE-2023-47320?
CVE-2023-47320 is categorized as an Incorrect Access Control vulnerability.