File tree Expand file tree Collapse file tree 8 files changed +16
-16
lines changed Expand file tree Collapse file tree 8 files changed +16
-16
lines changed Original file line number Diff line number Diff line change 1
- # CVE-2023 -47320: Denial of Service via Broken Access Control in Silverpeas Core
1
+ # CVE-2023 -47320: Silverpeas Core Denial of Service via Broken Access Control
2
2
3
3
## Information
4
4
** Description:** This allows denial-of-service by a low privileged user affecting the Silverpeas Core application. <br >
5
5
** Versions Affected:** < 6.3.1 <br >
6
6
** Version Fixed:** 6.3.2 <br >
7
7
** Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey )
8
- ** Disclosure Link:** https://rhinosecuritylabs.com/blog /
8
+ ** Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves /
9
9
** NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
10
10
11
11
## Proof-of-Concept Exploit
Original file line number Diff line number Diff line change 1
- # CVE-2023 -47321: Portlet Deployer Access via Broken Access Control in Silverpeas Core
1
+ # CVE-2023 -47321: Silverpeas Core Portlet Deployer Access via Broken Access Control
2
2
3
3
## Information
4
4
** Description:** This allows low privileged users to access the Portlet Deployment tool. <br >
5
5
** Versions Affected:** < 6.3.1 <br >
6
6
** Version Fixed:** 6.3.2 <br >
7
7
** Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey )
8
- ** Disclosure Link:** https://rhinosecuritylabs.com/blog /
8
+ ** Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves /
9
9
** NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
10
10
11
11
## Proof-of-Concept Exploit
Original file line number Diff line number Diff line change 1
- # CVE-2023 -47322: CSRF Leading to Privilege Escalation in Silverpeas Core
1
+ # CVE-2023 -47322: Silverpeas Core CSRF Leading to Privilege Escalation
2
2
3
3
## Information
4
4
** Description:** The "userModify" request is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. <br >
5
5
** Versions Affected:** < 6.3.1 <br >
6
6
** Version Fixed:** 6.3.2 <br >
7
7
** Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey )
8
- ** Disclosure Link:** https://rhinosecuritylabs.com/blog /
8
+ ** Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves /
9
9
** NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
10
10
11
11
## Proof-of-Concept Exploit
Original file line number Diff line number Diff line change 1
- # CVE-2023 -47323: Broken Access Control Allows Reading All Messages in Silverpeas Core
1
+ # CVE-2023 -47323: Silverpeas Core Broken Access Control Allows Reading All Messages
2
2
3
3
## Information
4
4
** Description:** The notification/messaging feature does not enforce access control on the ID parameter, allowing any user to read all messages (including admin-only messages). <br >
5
5
** Versions Affected:** < 6.3.1 <br >
6
6
** Version Fixed:** 6.3.2 <br >
7
7
** Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey )
8
- ** Disclosure Link:** https://rhinosecuritylabs.com/blog /
8
+ ** Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves /
9
9
** NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
10
10
11
11
## Proof-of-Concept Exploit
Original file line number Diff line number Diff line change 1
- # CVE-2023 -47324: Stored XSS in Messages affecting Silverpeas Core
1
+ # CVE-2023 -47324: Silverpeas Core Stored XSS in Messages
2
2
3
3
## Information
4
4
** Description:** The messaging feature of Silverpeas Core is vulnerable to Stored Cross-Site Scripting (XSS). <br >
5
5
** Versions Affected:** < 6.3.1 <br >
6
6
** Version Fixed:** 6.3.2 <br >
7
7
** Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey )
8
- ** Disclosure Link:** https://rhinosecuritylabs.com/blog /
8
+ ** Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves /
9
9
** NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
10
10
11
11
## Proof-of-Concept Exploit
Original file line number Diff line number Diff line change 1
- # CVE-2023 -47325: Broken Access Control on the "Bin" Allows Modification of Deleted Spaces in Silverpeas Core
1
+ # CVE-2023 -47325: Silverpeas Core Broken Access Control on the "Bin" Allows Modification of Deleted Spaces
2
2
3
3
## Information
4
4
** Description:** Broken Access Control on the "Bin" allows low privileged users to access and modify deleted spaces in Silverpeas Core. <br >
5
5
** Versions Affected:** < 6.3.1 <br >
6
6
** Version Fixed:** 6.3.2 <br >
7
7
** Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey )
8
- ** Disclosure Link:** https://rhinosecuritylabs.com/blog/
8
+ ** Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
9
9
** NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
10
10
11
11
## Proof-of-Concept Exploit
Original file line number Diff line number Diff line change 1
- # CVE-2023 -47326: Domain Creation is vulnerable to CSRF in Silverpeas Core
1
+ # CVE-2023 -47326: Silverpeas Core Domain Creation is vulnerable to CSRF
2
2
3
3
## Information
4
4
** Description:** Silverpeas Core is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function. <br >
5
5
** Versions Affected:** < 6.3.1 <br >
6
6
** Version Fixed:** 6.3.2 <br >
7
7
** Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey )
8
- ** Disclosure Link:** https://rhinosecuritylabs.com/blog/
8
+ ** Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves/
9
9
** NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
10
10
11
11
## Proof-of-Concept Exploit
Original file line number Diff line number Diff line change 1
- # CVE-2023 -47327: The Space Create Function in Silverpeas Core is vulnerable to Broken Access Control
1
+ # CVE-2023 -47327: Silverpeas Core Space Create Function is vulnerable to Broken Access Control
2
2
3
3
## Information
4
4
** Description:** The "create a space" feature in Silverpeas Core suffers from broken access control, allowing any user to create a space regardless of permissions. <br >
5
5
** Versions Affected:** < 6.3.1 <br >
6
6
** Version Fixed:** 6.3.2 <br >
7
7
** Researcher:** Tyler Ramsbey (https://youtube.com/@TylerRamsbey )
8
- ** Disclosure Link:** https://rhinosecuritylabs.com/blog /
8
+ ** Disclosure Link:** https://rhinosecuritylabs.com/research/silverpeas-file-read-cves /
9
9
** NIST CVE Link:** https://nvd.nist.gov/vuln/detail/CVE-2023-47320
10
10
11
11
## Proof-of-Concept Exploit
You can’t perform that action at this time.
0 commit comments