Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HSilverpeas
APPSilverpeas< 6.3.2
Related vulnerabilities
Silverpeas – pomijanie wymagań złożoności hasła przy jego zmianie
Silverpeas – pominięcie hasła umożliwia dostęp jako superadmin (Auth Bypass)
Path Traversal podczas uploadu plików w Silverpeas 5.15–6.0.2
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via t...
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading t...