CVE-2023-47324: XSS
Silverpeas Core 6.3.1 and prior are vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
Other sources
Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-configurationto a version that resolves this vulnerability.Fixed in 6.3.2 - Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-warto a version that resolves this vulnerability.Fixed in 6.3.2 - Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-apito a version that resolves this vulnerability.Fixed in 6.3.2 - Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-webto a version that resolves this vulnerability.Fixed in 6.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47324?
CVE-2023-47324 is considered to be a moderate severity vulnerability due to its potential for exploitation through Cross Site Scripting (XSS).
How do I fix CVE-2023-47324?
To fix CVE-2023-47324, upgrade to Silverpeas Core version 6.3.2 or later.
What are the potential impacts of CVE-2023-47324?
The potential impacts of CVE-2023-47324 include unauthorized access, data manipulation, and session hijacking through XSS attacks.
Which versions are affected by CVE-2023-47324?
Versions of Silverpeas Core prior to 6.3.2 are affected by CVE-2023-47324.
What does CVE-2023-47324 exploit in the Silverpeas Core application?
CVE-2023-47324 exploits the message/notification feature in Silverpeas Core, allowing for Cross Site Scripting (XSS) attacks.