← Vulnerability feed

Vulnerability record · CVE-2024-48814 · published 3 January 2025

CVE-2024-48814: Silverpeas sql injection vulnerability

Silverpeas · Silverpeas

SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function

7.5 CVSS 3.1 High EPSS 0.54% · top 56.7% CWE-89 · SQL injection
7.5CVSS 3.1 base score
0.54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-48814 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2018-19586Silverpeas path traversal vulnerabilitySilverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because cor…EPSS 5.0%9.8CVE-2024-42850Silverpeas weak password requirements vulnerabilityAn issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.EPSS 1.4%9.8CVE-2024-36042Silverpeas authentication bypass via alternate path vulnerabilitySilverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user…EPSS 0.94%8.8CVE-2023-47322Silverpeas cross-site request forgery vulnerabilityThe "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administr…EPSS 0.40%8.8CVE-2023-47326Silverpeas cross-site request forgery vulnerabilitySilverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.EPSS 0.38%8.1CVE-2023-47320Silverpeas incorrect authorization vulnerabilitySilverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function o…EPSS 0.72%7.5CVE-2023-47323Silverpeas vulnerabilityThe notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all …EPSS 0.77%6.5CVE-2025-46047Silverpeas improper input validation vulnerabilityA User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determin…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2024-48814), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.