Cross-Site Request Forgery Vulnerability in YesWiki Filemanager by YesWiki
CVE-2026-104452
5.3MEDIUM
What is CVE-2026-104452?
YesWiki versions before 4.6.7 are susceptible to a cross-site request forgery (CSRF) vulnerability within the filemanager page handler. This flaw allows attackers to exploit GET requests, enabling them to delete page attachments without proper verification of a CSRF token. An attacker could trick a logged-in page owner or administrator into navigating to a specially crafted URL that invokes actions such as 'do=del', 'erase', or 'emptytrash', resulting in the deletion or permanent removal of attachments associated with the page.
Affected Version(s)
yeswiki 0 < 4.6.7
yeswiki 4.6.7
