Description
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
Remediation
References
http://silverpeas.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47320
Related Vulnerabilities
CVE-2021-24122 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-7704 Vulnerability in npm package linux-cmdline
CVE-2020-36377 Vulnerability in npm package aaptjs
CVE-2019-18797 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2019-10759 Vulnerability in maven package org.webjars.npm:safer-eval