296,138
Total vulnerabilities in the database
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.
Software | From | Fixed in |
---|---|---|
![]() |
- | 6.3.2 |
![]() |
- | 6.3.2 |
silverpeas / silverpeas | - | 6.3.2 |