← Vulnerability feed

Vulnerability record · CVE-2023-47322 · published 13 December 2023

CVE-2023-47322: Silverpeas cross-site request forgery vulnerability

Silverpeas · Silverpeas

The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.

8.8 CVSS 3.1 High EPSS 0.40% · top 68.9% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
9 Jul 2026Last modified by NVD

Description

The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-47322 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2018-19586Silverpeas path traversal vulnerabilitySilverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because cor…EPSS 5.0%9.8CVE-2024-42850Silverpeas weak password requirements vulnerabilityAn issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.EPSS 1.4%9.8CVE-2024-36042Silverpeas authentication bypass via alternate path vulnerabilitySilverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user…EPSS 0.94%8.8CVE-2023-47326Silverpeas cross-site request forgery vulnerabilitySilverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.EPSS 0.38%8.1CVE-2023-47320Silverpeas incorrect authorization vulnerabilitySilverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function o…EPSS 0.72%7.5CVE-2024-48814Silverpeas sql injection vulnerabilitySQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywher…EPSS 0.54%7.5CVE-2023-47323Silverpeas vulnerabilityThe notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all …EPSS 0.77%6.5CVE-2025-46047Silverpeas improper input validation vulnerabilityA User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determin…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2023-47322), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.