Reflected Cross-Site Scripting Vulnerability in YesWiki by YesWiki
CVE-2025-46350
4.8MEDIUM
What is CVE-2025-46350?
YesWiki, a PHP-based wiki system, is vulnerable to a reflected cross-site scripting (XSS) attack in versions prior to 4.5.4. This vulnerability allows an attacker to craft a malicious link that, when clicked by an authenticated user, can lead to the theft of cookies. With access to these cookies, attackers can hijack user sessions, posing serious risks such as session takeover and website defacement. Users are advised to upgrade to version 4.5.4 or later to mitigate these security risks.
Affected Version(s)
yeswiki < 4.5.4