Description
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the spaces.
Remediation
References
http://silverpeas.com
https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47325
Related Vulnerabilities
CVE-2023-49371 Vulnerability in maven package com.ruoyi:ruoyi
CVE-2020-7680 Vulnerability in npm package docsify
CVE-2023-49145 Vulnerability in maven package org.apache.nifi:nifi-jolt-transform-json-ui
CVE-2022-29567 Vulnerability in maven package com.vaadin:vaadin-grid-flow
CVE-2022-36883 Vulnerability in maven package org.jenkins-ci.plugins:git