Silverpeas

Silverpeas

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Veröffentlicht 02.09.2025 00:00:00
  • Zuletzt bearbeitet 04.09.2025 17:46:45

A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login parameter.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 09.06.2025 00:00:00
  • Zuletzt bearbeitet 25.06.2025 20:24:56

Silverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can upload a malicious SVG file as an event attachment, which, when viewed by an administrator, executes embedded JavaSc...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 22.01.2025 21:15:09
  • Zuletzt bearbeitet 28.05.2025 20:41:45

Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious ...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 03.01.2025 15:15:10
  • Zuletzt bearbeitet 28.05.2025 20:15:50

SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function

Exploit
  • EPSS 49.78%
  • Veröffentlicht 16.08.2024 19:15:10
  • Zuletzt bearbeitet 05.06.2025 14:04:02

An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

Exploit
  • EPSS 11.35%
  • Veröffentlicht 16.08.2024 19:15:10
  • Zuletzt bearbeitet 05.06.2025 14:04:16

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

Exploit
  • EPSS 6.74%
  • Veröffentlicht 09.07.2024 21:15:15
  • Zuletzt bearbeitet 05.06.2025 14:03:30

In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 03.06.2024 06:15:09
  • Zuletzt bearbeitet 29.05.2025 20:21:54

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 22.05.2024 16:15:09
  • Zuletzt bearbeitet 23.04.2025 01:53:40

Silverpeas Core 6.3 is vulnerable to Cross Site Scripting (XSS) via ClipboardSessionController.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 13.12.2023 14:15:44
  • Zuletzt bearbeitet 21.11.2024 08:30:10

The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.