PT-2023-30419 · Unknown · Silverpeas Core

Tyler Ramsbey

·

Published

2023-12-13

·

Updated

2023-12-18

·

CVE-2023-47326

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Silverpeas Core version 6.3.1
Description The issue is related to Cross Site Request Forgery (CSRF) via the Domain SQL Create function. This means that an attacker could potentially trick a user into performing unintended actions on the application.
Recommendations For Silverpeas Core version 6.3.1, consider disabling the Domain SQL Create function until a patch is available to prevent potential CSRF attacks. Restrict access to this function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-47326
GHSA-GQGV-7WPJ-VM6Q

Affected Products

Silverpeas Core