logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-47323

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-47323

Description:
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.
Last updated date:
12/15/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
12/15/2023
Reference url to background

https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47323

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy