Skip to content

Commit 5a9b5b5

Browse files
authored
Merge pull request #10 from TeneBrae93/master
Silverpeas Title Updates & Blog Post
2 parents 8e58c8f + 526940a commit 5a9b5b5

File tree

8 files changed

+16
-16
lines changed

8 files changed

+16
-16
lines changed

CVE-2023-47320/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
1-
# CVE-2023-47320: Denial of Service via Broken Access Control in Silverpeas Core
1+
# CVE-2023-47320: Silverpeas Core Denial of Service via Broken Access Control
22

33
## Information
44
**Description:** This allows denial-of-service by a low privileged user affecting the Silverpeas Core application. <br>
55
**Versions Affected:** < 6.3.1 <br>
66
**Version Fixed:** 6.3.2 <br>
77
**Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey)
8-
**Disclosure Link:** https://rhinosecuritylabs.com/blog/
8+
**Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
99
**NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
1010

1111
## Proof-of-Concept Exploit

CVE-2023-47321/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
1-
# CVE-2023-47321: Portlet Deployer Access via Broken Access Control in Silverpeas Core
1+
# CVE-2023-47321: Silverpeas Core Portlet Deployer Access via Broken Access Control
22

33
## Information
44
**Description:** This allows low privileged users to access the Portlet Deployment tool. <br>
55
**Versions Affected:** < 6.3.1 <br>
66
**Version Fixed:** 6.3.2 <br>
77
**Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey)
8-
**Disclosure Link:** https://rhinosecuritylabs.com/blog/
8+
**Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
99
**NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
1010

1111
## Proof-of-Concept Exploit

CVE-2023-47322/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
1-
# CVE-2023-47322: CSRF Leading to Privilege Escalation in Silverpeas Core
1+
# CVE-2023-47322: Silverpeas Core CSRF Leading to Privilege Escalation
22

33
## Information
44
**Description:** The "userModify" request is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. <br>
55
**Versions Affected:** < 6.3.1 <br>
66
**Version Fixed:** 6.3.2 <br>
77
**Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey)
8-
**Disclosure Link:** https://rhinosecuritylabs.com/blog/
8+
**Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
99
**NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
1010

1111
## Proof-of-Concept Exploit

CVE-2023-47323/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
1-
# CVE-2023-47323: Broken Access Control Allows Reading All Messages in Silverpeas Core
1+
# CVE-2023-47323: Silverpeas Core Broken Access Control Allows Reading All Messages
22

33
## Information
44
**Description:** The notification/messaging feature does not enforce access control on the ID parameter, allowing any user to read all messages (including admin-only messages). <br>
55
**Versions Affected:** < 6.3.1 <br>
66
**Version Fixed:** 6.3.2 <br>
77
**Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey)
8-
**Disclosure Link:** https://rhinosecuritylabs.com/blog/
8+
**Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
99
**NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
1010

1111
## Proof-of-Concept Exploit

CVE-2023-47324/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
1-
# CVE-2023-47324: Stored XSS in Messages affecting Silverpeas Core
1+
# CVE-2023-47324: Silverpeas Core Stored XSS in Messages
22

33
## Information
44
**Description:** The messaging feature of Silverpeas Core is vulnerable to Stored Cross-Site Scripting (XSS). <br>
55
**Versions Affected:** < 6.3.1 <br>
66
**Version Fixed:** 6.3.2 <br>
77
**Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey)
8-
**Disclosure Link:** https://rhinosecuritylabs.com/blog/
8+
**Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
99
**NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
1010

1111
## Proof-of-Concept Exploit

CVE-2023-47325/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
1-
# CVE-2023-47325: Broken Access Control on the "Bin" Allows Modification of Deleted Spaces in Silverpeas Core
1+
# CVE-2023-47325: Silverpeas Core Broken Access Control on the "Bin" Allows Modification of Deleted Spaces
22

33
## Information
44
**Description:** Broken Access Control on the "Bin" allows low privileged users to access and modify deleted spaces in Silverpeas Core. <br>
55
**Versions Affected:** < 6.3.1 <br>
66
**Version Fixed:** 6.3.2 <br>
77
**Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey)
8-
**Disclosure Link:** https://rhinosecuritylabs.com/blog/
8+
**Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
99
**NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
1010

1111
## Proof-of-Concept Exploit

CVE-2023-47326/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
1-
# CVE-2023-47326: Domain Creation is vulnerable to CSRF in Silverpeas Core
1+
# CVE-2023-47326: Silverpeas Core Domain Creation is vulnerable to CSRF
22

33
## Information
44
**Description:** Silverpeas Core is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function. <br>
55
**Versions Affected:** < 6.3.1 <br>
66
**Version Fixed:** 6.3.2 <br>
77
**Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey)
8-
**Disclosure Link:** https://rhinosecuritylabs.com/blog/
8+
**Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
99
**NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
1010

1111
## Proof-of-Concept Exploit

CVE-2023-47327/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
1-
# CVE-2023-47327: The Space Create Function in Silverpeas Core is vulnerable to Broken Access Control
1+
# CVE-2023-47327: Silverpeas Core Space Create Function is vulnerable to Broken Access Control
22

33
## Information
44
**Description:** The "create a space" feature in Silverpeas Core suffers from broken access control, allowing any user to create a space regardless of permissions. <br>
55
**Versions Affected:** < 6.3.1 <br>
66
**Version Fixed:** 6.3.2 <br>
77
**Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey)
8-
**Disclosure Link:** https://rhinosecuritylabs.com/blog/
8+
**Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
99
**NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
1010

1111
## Proof-of-Concept Exploit

0 commit comments

Comments
 (0)