PT-2025-18210 · Yeswiki · Yeswiki

Pizza-Power

·

Published

2025-04-29

·

Updated

2025-04-30

·

CVE-2025-46348

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YesWiki versions prior to 4.5.4
Description The issue allows a malicious user to create and download site backups without authentication. This could result in a malicious attacker making numerous requests to create archives and fill up the file system, or by downloading the archive which contains sensitive site information. The request to commence a site backup can be performed and downloaded without authentication due to a predictable filename used for the archives.
Recommendations For versions prior to 4.5.4, update to version 4.5.4 to resolve the issue. As a temporary workaround, consider restricting access to the site backup functionality until the update is applied.

Exploit

Fix

Improper Authentication

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-46348
GHSA-WC9G-6J9W-HR95

Affected Products

Yeswiki