CVE-2025-46550

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*

History

09 May 2025, 13:59

Type Values Removed Values Added
First Time Yeswiki
Yeswiki yeswiki
References () https://github.com/YesWiki/yeswiki/commit/4e9e51d80cd024ed2ac5c12c820817e6d8c2655a - () https://github.com/YesWiki/yeswiki/commit/4e9e51d80cd024ed2ac5c12c820817e6d8c2655a - Patch
References () https://github.com/YesWiki/yeswiki/security/advisories/GHSA-ggqx-43h2-55jp - () https://github.com/YesWiki/yeswiki/security/advisories/GHSA-ggqx-43h2-55jp - Exploit, Vendor Advisory
CPE cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*

30 Apr 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) YesWiki es un sistema wiki escrito en PHP. Antes de la versión 4.5.4, el endpoint `/?BazaR` y el parámetro `idformulaire` eran vulnerables a ataques de cross-site scripting. Un atacante puede usar un ataque de cross-site scripting reflejado para robar cookies de un usuario autenticado al hacer que haga clic en un enlace malicioso. Las cookies robadas permiten al atacante controlar la sesión del usuario. Esta vulnerabilidad también puede permitir a los atacantes desfigurar el sitio web o incrustar contenido malicioso. Este problema se ha corregido en la versión 4.5.4.
References () https://github.com/YesWiki/yeswiki/security/advisories/GHSA-ggqx-43h2-55jp - () https://github.com/YesWiki/yeswiki/security/advisories/GHSA-ggqx-43h2-55jp -

29 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 21:15

Updated : 2025-05-09 13:59


NVD link : CVE-2025-46550

Mitre link : CVE-2025-46550

CVE.ORG link : CVE-2025-46550


JSON object : View

Products Affected

yeswiki

  • yeswiki
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')