CVE-2023-47323: High severity Silverpeas Silverpeas vulnerability
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-webto a version that resolves this vulnerability.Fixed in 6.3.2 - Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-apito a version that resolves this vulnerability.Fixed in 6.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47323?
CVE-2023-47323 is classified as a high severity vulnerability due to its potential to expose sensitive message data to unauthorized users.
How do I fix CVE-2023-47323?
To mitigate CVE-2023-47323, upgrade to Silverpeas Core version 6.3.2 or later, which implements proper access control.
What types of data are exposed by CVE-2023-47323?
CVE-2023-47323 allows attackers to read messages exchanged between users, including messages intended only for administrators.
Which software versions are affected by CVE-2023-47323?
CVE-2023-47323 affects Silverpeas Core versions prior to 6.3.2.
Who is at risk from CVE-2023-47323?
Any users of Silverpeas Core 6.3.1 or earlier are at risk, especially those who exchange sensitive messages.