CVE-2025-46350

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*

History

09 May 2025, 13:57

Type Values Removed Values Added
First Time Yeswiki
Yeswiki yeswiki
References () https://github.com/YesWiki/yeswiki/commit/e2603176a4607b83659635a0c517550d4a171cb9 - () https://github.com/YesWiki/yeswiki/commit/e2603176a4607b83659635a0c517550d4a171cb9 - Patch
References () https://github.com/YesWiki/yeswiki/security/advisories/GHSA-cg4f-cq8h-3ch8 - () https://github.com/YesWiki/yeswiki/security/advisories/GHSA-cg4f-cq8h-3ch8 - Exploit, Vendor Advisory
CPE cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) YesWiki es un sistema wiki escrito en PHP. Antes de la versión 4.5.4, un atacante podía usar un ataque de cross-site scripting reflejado para robar cookies de un usuario autenticado al hacer que hiciera clic en un enlace malicioso. Las cookies robadas permiten al atacante controlar la sesión del usuario. Esta vulnerabilidad también puede permitir a los atacantes desfigurar el sitio web o incrustar contenido malicioso. Este problema se ha corregido en la versión 4.5.4.

29 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 18:15

Updated : 2025-05-09 13:57


NVD link : CVE-2025-46350

Mitre link : CVE-2025-46350

CVE.ORG link : CVE-2025-46350


JSON object : View

Products Affected

yeswiki

  • yeswiki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')