CVE-2024-56923

Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. The attack can lead to session hijacking, data theft, or unauthorized actions when an admin user views the affected subscription.
Configurations

Configuration 1 (hide)

cpe:2.3:a:silverpeas:silverpeas:*:*:*:*:*:*:*:*

History

28 May 2025, 20:41

Type Values Removed Values Added
First Time Silverpeas
Silverpeas silverpeas
CPE cpe:2.3:a:silverpeas:silverpeas:*:*:*:*:*:*:*:*
References () https://github.com/Mohamed-Saqib-C/CVEs/blob/main/CVE-2024-56923/README.md - () https://github.com/Mohamed-Saqib-C/CVEs/blob/main/CVE-2024-56923/README.md - Exploit, Third Party Advisory

28 Jan 2025, 23:15

Type Values Removed Values Added
Summary (en) Stored Cross-Site Scripting (XSS) in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. The attack can lead to session hijacking, data theft, or unauthorized actions when an admin user views the affected subscription. (en) Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. The attack can lead to session hijacking, data theft, or unauthorized actions when an admin user views the affected subscription.

23 Jan 2025, 17:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References () https://github.com/Mohamed-Saqib-C/CVEs/blob/main/CVE-2024-56923/README.md - () https://github.com/Mohamed-Saqib-C/CVEs/blob/main/CVE-2024-56923/README.md -
Summary
  • (es) Cross-Site Scripting (XSS) Almacenado en Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.4.1 permite que un atacante remoto ejecute código JavaScript arbitrario. Esto se logra mediante inyectando un payload malicioso en el campo Nombre de una suscripción. El ataque puede provocar secuestro de sesión, robo de datos o acciones no autorizadas cuando un usuario administrador ve la suscripción afectada.

22 Jan 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-22 21:15

Updated : 2025-05-28 20:41


NVD link : CVE-2024-56923

Mitre link : CVE-2024-56923

CVE.ORG link : CVE-2024-56923


JSON object : View

Products Affected

silverpeas

  • silverpeas
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')