Reflected Cross-Site Scripting Vulnerability in YesWiki PHP System
CVE-2025-46550

6.1MEDIUM

Key Information:

Vendor

Yeswiki

Status
Vendor
CVE Published:
29 April 2025

What is CVE-2025-46550?

YesWiki, a wiki system developed in PHP, is susceptible to a reflected cross-site scripting (XSS) vulnerability through its /?BazaR endpoint and the idformulaire parameter. This issue allows attackers to exploit the vulnerability by persuading authenticated users to click on malicious links. When this occurs, attackers can steal session cookies, potentially leading to session hijacking. The vulnerability also poses risks of website defacement and the injection of malicious content. Users are urged to upgrade to version 4.5.4, which includes necessary patches to mitigate these security threats.

Affected Version(s)

yeswiki < 4.5.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.