org.silverpeas.core:silverpeas-core-web
Maven9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.silverpeas.core:silverpeas-core-webpage 1 of 1
- CVE-2023-47320HIGHCVSS 8.1EG 8.1✓ Fixed in 6.3.22023-12-13
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes t…
- CVE-2023-47321MEDIUMCVSS 4.9EG 4.9✓ Fixed in 6.3.22023-12-13
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets.
- CVE-2023-47322HIGHCVSS 8.8EG 8.8✓ Fixed in 6.3.22023-12-13
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the …
- CVE-2023-47323HIGHCVSS 7.5EG 7.5✓ Fixed in 6.3.22023-12-13
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.
- CVE-2023-47324MEDIUMCVSS 5.4EG 5.4✓ Fixed in 6.3.22023-12-13
Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
- CVE-2023-47325MEDIUMCVSS 5.4EG 5.4✓ Fixed in 6.3.22023-12-13
Silverpeas Core 6.3.1 administrative "Bin" feature is affected by broken access control. A user with low privileges is able to navigate directly to the bin, revealing all deleted spaces. The user can then restore or permanently delete the …
- CVE-2023-47327MEDIUMCVSS 4.3EG 4.3✓ Fixed in 6.3.22023-12-13
The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.
- CVE-2024-39031MEDIUMCVSS 5.4EG 5.42024-07-09
In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an …
- CVE-2026-30139MEDIUMCVSS 6.1EG 6.12026-04-22
A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before version 6.4.6 allows attackers to execute arbitrary JavaScript in the context of a user's browser via crafted input.
Check whether org.silverpeas.core:silverpeas-core-web is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.silverpeas.core:silverpeas-core-web CVEs against the assets you own.
Start Free Scan →