PT-2025-14120 · Yeswiki · Yeswiki

Masquerad3R

·

Published

2025-04-01

·

Updated

2025-06-07

·

CVE-2025-31131

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions YesWiki versions prior to 4.5.2
Description The issue concerns a path traversal vulnerability in the squelette parameter, allowing unauthorized access to server files. This enables read access to arbitrary files on the server.
Recommendations For versions prior to 4.5.2, update to version 4.5.2 to fix this security flaw. As a temporary workaround, consider restricting access to the squelette parameter to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-31131
GHSA-W34W-FVP3-68XM

Affected Products

Yeswiki