CVE-2025-46549

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*

History

09 May 2025, 13:59

Type Values Removed Values Added
References () https://github.com/YesWiki/yeswiki/commit/107d43056adebaa0c731230f9fd010898e88f3f5 - () https://github.com/YesWiki/yeswiki/commit/107d43056adebaa0c731230f9fd010898e88f3f5 - Patch
References () https://github.com/YesWiki/yeswiki/security/advisories/GHSA-r9gv-qffm-xw6f - () https://github.com/YesWiki/yeswiki/security/advisories/GHSA-r9gv-qffm-xw6f - Exploit, Vendor Advisory
CPE cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Yeswiki
Yeswiki yeswiki

30 Apr 2025, 14:15

Type Values Removed Values Added
CWE CWE-79

29 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 21:15

Updated : 2025-05-09 13:59


NVD link : CVE-2025-46549

Mitre link : CVE-2025-46549


JSON object : View

Products Affected

yeswiki

  • yeswiki
CWE

No CWE.