CVE-2023-47322: CSRF
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-webto a version that resolves this vulnerability.Fixed in 6.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47322?
CVE-2023-47322 is classified as a high severity vulnerability due to its potential for privilege escalation through CSRF exploitation.
How do I fix CVE-2023-47322?
To remediate CVE-2023-47322, upgrade Silverpeas Core to version 6.3.2 or later.
What is CVE-2023-47322 about?
CVE-2023-47322 involves a vulnerability in the 'userModify' feature of Silverpeas Core that allows CSRF attacks, facilitating unauthorized privilege escalation.
Who is affected by CVE-2023-47322?
CVE-2023-47322 affects users of Silverpeas Core versions prior to 6.3.2, specifically those with administrative privileges.
What types of attacks can occur with CVE-2023-47322?
With CVE-2023-47322, attackers can exploit CSRF to assume administrator privileges if a targeted administrator visits a malicious URL.