← Vulnerability feed

Vulnerability record · CVE-2018-19586 · published 9 April 2019

CVE-2018-19586: Silverpeas path traversal vulnerability

Silverpeas · Silverpeas

Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call. This vulnerability enables regular users to write arbitrary files on the underlying system with privileges of the user running the application. Especially, an attacker may leverage the vulnerability to write an executable JSP file in an exposed web directory to execute commands on the underlying system.

9.9 CVSS 3.0 Critical EPSS 5.0% · top 8.0% CWE-22 · Path traversal
9.9CVSS 3.0 base score, v2 9.0
5.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call. This vulnerability enables regular users to write arbitrary files on the underlying system with privileges of the user running the application. Especially, an attacker may leverage the vulnerability to write an executable JSP file in an exposed web directory to execute commands on the underlying system.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-19586 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-42850Silverpeas weak password requirements vulnerabilityAn issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.EPSS 1.4%9.8CVE-2024-36042Silverpeas authentication bypass via alternate path vulnerabilitySilverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user…EPSS 0.94%8.8CVE-2023-47322Silverpeas cross-site request forgery vulnerabilityThe "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administr…EPSS 0.40%8.8CVE-2023-47326Silverpeas cross-site request forgery vulnerabilitySilverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.EPSS 0.38%8.1CVE-2023-47320Silverpeas incorrect authorization vulnerabilitySilverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function o…EPSS 0.72%7.5CVE-2024-48814Silverpeas sql injection vulnerabilitySQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywher…EPSS 0.54%7.5CVE-2023-47323Silverpeas vulnerabilityThe notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all …EPSS 0.77%6.5CVE-2025-46047Silverpeas improper input validation vulnerabilityA User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determin…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2018-19586), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.