PT-2025-18195 · Yeswiki · Yeswiki

Pizza-Power

·

Published

2025-04-29

·

Updated

2025-05-02

·

CVE-2025-46347

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YesWiki versions prior to 4.5.4
Description YesWiki, a wiki system written in PHP, is susceptible to remote code execution. This issue arises from an arbitrary file write capability, which can be exploited to create a file with a PHP extension. An attacker can then browse to this file, executing arbitrary code on the server and potentially leading to a full server compromise. This exploitation could occur unintentionally through user actions.
Recommendations For versions prior to 4.5.4, update to version 4.5.4 to resolve the issue.

Exploit

Fix

RCE

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2025-46347
GHSA-88XG-V53P-FPVF

Affected Products

Yeswiki