Executive brief
Silverpeas Core is an enterprise collaboration and content management platform. A stored cross-site scripting (XSS) vulnerability in the Document management file upload feature allows authenticated users with specific roles to inject malicious JavaScript that executes when other users preview uploaded files, potentially leading to account compromise or data theft.
Technical details
The Document management application in Silverpeas Core 6.4.6 fails to sanitize the X-FULL-PATH header during file upload operations. An authenticated attacker with Manager, Publisher, or Writer role can intercept the upload request and replace this header with a JavaScript payload (e.g., <img src=x onerror=prompt(1);>). The payload is stored server-side and executed in the browser when a user clicks the file preview button. This is a stored XSS vulnerability accessible to authenticated users on the network. The vulnerability was fixed in version 6.4.7.
Affected products
- Silverpeas Silverpeas Core 6.4.6
Timeline
- 2026-09-08: disclosed: CVE-2026-78738 published on NVD
- 2026-09-05: patched: Fixed in version 6.4.7