First published: Wed Dec 13 2023(Updated: )
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.silverpeas.core:silverpeas-core-web | <6.3.2 | 6.3.2 |
Silverpeas Core | <6.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47322 is classified as a high severity vulnerability due to its potential for privilege escalation through CSRF exploitation.
To remediate CVE-2023-47322, upgrade Silverpeas Core to version 6.3.2 or later.
CVE-2023-47322 involves a vulnerability in the 'userModify' feature of Silverpeas Core that allows CSRF attacks, facilitating unauthorized privilege escalation.
CVE-2023-47322 affects users of Silverpeas Core versions prior to 6.3.2, specifically those with administrative privileges.
With CVE-2023-47322, attackers can exploit CSRF to assume administrator privileges if a targeted administrator visits a malicious URL.