---
cve: "CVE-2023-47323"
severity: "LOW"
cvss: 3.1
epss: "77%"
vendor: "n/a"
kev: false
exploited: false
published: "2023-12-13 14:15:44"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T09:26:03+02:00"
---

# CVE-2023-47323

> 3.1 LOW · 🧪 PoC

## Beschreibung

The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.

## Patch verfügbar (OSV)

- be7d7d580572c31f28e80e84dc3813c4ae6f6bd2 (Commit)

## Referenzen

- <https://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2023-47323>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-47323) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
