296,772
Total vulnerabilities in the database
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.
| Software | From | Fixed in |
|---|---|---|
org.silverpeas.core / silverpeas-core-api
|
- | 6.3.2 |
org.silverpeas.core / silverpeas-core-web
|
- | 6.3.2 |
| silverpeas / silverpeas | - | 6.3.2 |