Reflected Cross-Site Scripting Vulnerability in YesWiki PHP System
CVE-2025-46550
6.1MEDIUM
What is CVE-2025-46550?
YesWiki, a wiki system developed in PHP, is susceptible to a reflected cross-site scripting (XSS) vulnerability through its /?BazaR
endpoint and the idformulaire
parameter. This issue allows attackers to exploit the vulnerability by persuading authenticated users to click on malicious links. When this occurs, attackers can steal session cookies, potentially leading to session hijacking. The vulnerability also poses risks of website defacement and the injection of malicious content. Users are urged to upgrade to version 4.5.4, which includes necessary patches to mitigate these security threats.
Affected Version(s)
yeswiki < 4.5.4