Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.silverpeas.core:silverpeas-core-war(Maven) | 0 | 6.3.2 | N/A |
| org.silverpeas.core:silverpeas-core-web(Maven) | 0 | 6.3.2 | N/A |
CVSS Metrics