PT-2026-37109 · Yeswiki · Yeswiki

Morimori-Dev

·

Published

2026-04-18

·

Updated

2026-05-07

·

CVE-2026-41143

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YesWiki versions prior to 4.6.1
Description The bazar module contains a SQL injection flaw in the tools/bazar/services/EntryManager.php file. The issue occurs because the id fiche value, sourced from the $ POST['id fiche'] variable, is concatenated directly into a raw SQL query without sanitization or parameterization. This allows an authenticated user to execute arbitrary SQL commands via the '/api/entries/{formId}' endpoint by manipulating the id fiche parameter. The vulnerability is triggered within the create() function, which calls formatDataBeforeSave(), eventually passing the unsanitized input to the loadSingle() function.
Recommendations Update to version 4.6.1. As a temporary workaround, restrict access to the '/api/entries/{formId}' endpoint or avoid using the id fiche parameter until the update is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-41143
GHSA-F58V-P6J9-24C2

Affected Products

Yeswiki