PT-2025-18195 · Yeswiki · Yeswiki
Pizza-Power
·
Published
2025-04-29
·
Updated
2025-05-02
·
CVE-2025-46347
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
YesWiki versions prior to 4.5.4
Description
YesWiki, a wiki system written in PHP, is susceptible to remote code execution. This issue arises from an arbitrary file write capability, which can be exploited to create a file with a PHP extension. An attacker can then browse to this file, executing arbitrary code on the server and potentially leading to a full server compromise. This exploitation could occur unintentionally through user actions.
Recommendations
For versions prior to 4.5.4, update to version 4.5.4 to resolve the issue.
Exploit
Fix
RCE
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yeswiki