Moderate severityNVD Advisory· Published Jan 22, 2025· Updated Jan 28, 2025
CVE-2024-56923
CVE-2024-56923
Description
Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. The attack can lead to session hijacking, data theft, or unauthorized actions when an admin user views the affected subscription.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.silverpeas.core:silverpeas-coreMaven | >= 6.3.1, < 6.4.2 | 6.4.2 |
Affected products
2- Silverpeas/Coredescription
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.