Silverpeas mishandles the "Personal space" feature that is selected when no componentId is set
Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.
Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.
A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core allows attackers to execute arbitrary JavaScript in the context of a user's browser via crafted input.
Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control. An attacker with low privileges is able to execute the administrator-only function of putting the application in "Maintenance Mode" due to broken access control. This makes the application unavailable to all users. This affects Silverpeas Core 6.3.1 and below.