Medium severity5.4NVD Advisory· Published Jan 22, 2025· Updated Jun 17, 2026
CVE-2024-56923
CVE-2024-56923
Description
Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. The attack can lead to session hijacking, data theft, or unauthorized actions when an admin user views the affected subscription.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.silverpeas.core:silverpeas-coreMaven | >= 6.3.1, < 6.4.2 | 6.4.2 |
Affected products
3- Silverpeas/Coredescription
Patches
Vulnerability mechanics
References
4- github.com/Mohamed-Saqib-C/CVEs/blob/main/CVE-2024-56923/README.mdnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-788m-27g4-cf86ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-56923ghsaADVISORY
- github.com/Silverpeas/Silverpeas-Core/pull/1373ghsaWEB
News mentions
0No linked articles in our index yet.