VYPR
High severity7.5NVD Advisory· Published Dec 13, 2023· Updated Jul 9, 2026

CVE-2023-47323

CVE-2023-47323

Description

The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.silverpeas.core:silverpeas-core-apiMaven
< 6.3.26.3.2
org.silverpeas.core:silverpeas-core-webMaven
< 6.3.26.3.2

Affected products

4

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.