The "Create a Space" feature in Silverpeas Core 6.3.1 is reserved for use by administrators. This function suffers from broken access control, allowing any authenticated user to create a space by navigating to the correct URL.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.silverpeas.core:silverpeas-core-web(Maven) | 0 | 6.3.2 | N/A |
CVSS Metrics