Unauthorized Backup Command Execution in YesWiki PHP System
CVE-2025-46348
9.8CRITICAL
What is CVE-2025-46348?
YesWiki, a PHP-based wiki system, presents a serious vulnerability prior to version 4.5.4, where an unauthorized request can trigger the site's backup process without any form of authentication. This flaw allows malicious users to generate and download backups with predictable filenames, potentially leading to unauthorized access to sensitive site information and the possibility of overwhelming the file system through excessive backup requests. This vulnerability has been addressed in the latest version, enhancing the system's security against such unauthorized access.
Affected Version(s)
yeswiki < 4.5.4
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
