Executive brief
Silverpeas Core is a collaborative portal and document management platform. An authenticated attacker can upload a malicious image file with a JavaScript payload in the filename, which executes when another user interacts with the uploaded file, potentially allowing account compromise or unauthorized actions within the portal.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the wysiwyg-CKEditor image upload feature of Silverpeas Core. The vulnerability occurs because the application fails to properly sanitize filenames during the image upload process. An authenticated attacker can intercept the upload request and replace the filename with a JavaScript payload (e.g., a form button with a javascript: URI), which is then stored and executed in the victim's browser when the file properties are viewed or the delete operation is triggered. The attack requires authentication and user interaction to trigger the payload execution. Silverpeas Core versions 6.4.6 and earlier are affected; version 6.4.7 contains the fix.
Affected products
- Silverpeas Core <=6.4.6
Timeline
- 2026-09-05: disclosed
- 2026-09-05: patched: Fixed in version 6.4.7