-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability explicitly references the 'Domain SQL Create' function as the attack vector. CSRF vulnerabilities typically occur in state-changing operations that lack anti-CSRF protections. While exact code isn't available, the function name and vulnerability description strongly indicate the domain creation endpoint processes requests without proper CSRF token validation. The high confidence comes from the specific vulnerability description matching common CSRF patterns in web applications.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.silverpeas.core:silverpeas-core | maven | < 6.3.2 | 6.3.2 |
KEV Misses 88% of Exploited CVEs- Get the report