PT-2025-3348 · Unknown · Silverpeas Core

Mohamed Saqib C

·

Published

2025-01-22

·

Updated

2025-01-23

·

CVE-2024-56923

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Silverpeas Core versions 6.3.1 through 6.4.1
Description The issue is related to a Stored Cross-Site Scripting (XSS) vulnerability in the Categorization Option of the My Subscriptions functionality. A remote attacker can execute arbitrary JavaScript code by injecting a malicious payload into the Name field of a subscription. This can lead to session hijacking, data theft, or unauthorized actions when an admin user views the affected subscription.
Recommendations For Silverpeas Core versions 6.3.1 through 6.4.1, consider disabling the Categorization Option of the My Subscriptions functionality until a patch is available. Restrict access to the My Subscriptions feature to minimize the risk of exploitation. Avoid using the Name field in the affected subscription functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56923
GHSA-788M-27G4-CF86

Affected Products

Silverpeas Core