CVE-2023-47327: Medium severity Silverpeas Silverpeas vulnerability
The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.silverpeas.core:silverpeas-core-webto a version that resolves this vulnerability.Fixed in 6.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47327?
CVE-2023-47327 is classified as a high severity vulnerability due to the risk of unauthorized space creation by authenticated users.
How do I fix CVE-2023-47327?
To fix CVE-2023-47327, upgrade to Silverpeas Core version 6.3.2 or higher.
Who is affected by CVE-2023-47327?
Any organization utilizing Silverpeas Core version 6.3.1 is at risk from CVE-2023-47327.
What type of vulnerability is CVE-2023-47327?
CVE-2023-47327 is categorized as a broken access control vulnerability.
Can I mitigate CVE-2023-47327 without upgrading?
Mitigating CVE-2023-47327 without upgrading is difficult and not recommended, as it fundamentally requires changes to the access control implementation.