GHSA-vfwh-gvf6-mff8 · Severity: medium · Ecosystem: maven — Silverpeas Core Cross-site Scripting vulnerability
In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, users can invite others from the same domain, including administrators, to these events. A standard user can inject an XSS payload into the "Titre" and "Description" fields when creating an event and then add the administrator or any user to the event. When the invited user (victim) views their own profile, the payload will be executed on their side, even if they do not click on the event.
Conclusion & alert: CVE-2024-39031 is rated High Exploit Risk (70.1/100): CVSS Medium severity, with high exploitation likelihood (EPSS 6.74%, 91th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.66% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-28 | 5.08% | 6.74% | +1.66% |
| 2 | 2025-11-21 | 3.05% | 5.08% | +2.03% |
| 3 | 2025-11-18 | — | 3.05% | — |
Full EPSS history (21 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.4 | 3.1 | MEDIUM |
|
2.3 | 2.7 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-vfwh-gvf6-mff8 · Severity: medium · Ecosystem: maven — Silverpeas Core Cross-site Scripting vulnerability
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| silverpeas | silverpeas | < 6.4 | cpe:2.3:a:silverpeas:silverpeas:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/toneemarqus/CVE-2024-39031 | Exploit Patch Third Party Advisory |
| https://www.github.com/Silverpeas/Silverpeas-Core/pull/1346 | Issue Tracking Patch |