Silverpeas

Silverpeas

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.52%
  • Veröffentlicht 13.12.2023 14:15:44
  • Zuletzt bearbeitet 21.11.2024 08:30:10

The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.

Exploit
  • EPSS 0.39%
  • Veröffentlicht 13.12.2023 14:15:44
  • Zuletzt bearbeitet 21.11.2024 08:30:10

Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.

Exploit
  • EPSS 0.42%
  • Veröffentlicht 13.12.2023 14:15:44
  • Zuletzt bearbeitet 22.05.2025 19:15:36

Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.

Exploit
  • EPSS 0.6%
  • Veröffentlicht 13.12.2023 14:15:44
  • Zuletzt bearbeitet 21.11.2024 08:30:09

Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.

Exploit
  • EPSS 0.79%
  • Veröffentlicht 13.12.2023 14:15:44
  • Zuletzt bearbeitet 21.11.2024 08:30:09

The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 13.12.2023 14:15:44
  • Zuletzt bearbeitet 21.11.2024 08:30:09

The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with e...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 13.12.2023 14:15:44
  • Zuletzt bearbeitet 21.11.2024 08:30:09

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.

Exploit
  • EPSS 0.74%
  • Veröffentlicht 13.12.2023 14:15:44
  • Zuletzt bearbeitet 22.05.2025 19:15:36

Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the applicat...

Exploit
  • EPSS 5.14%
  • Veröffentlicht 09.04.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:58:14

Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call. This vulnerability enables reg...