CyberRota Analysis
AI-GeneratedYesWiki versions prior to 4.6.7 are vulnerable to an empty-filter scope bypass in the triples delete API, allowing authenticated users to delete or manipulate arbitrary semantic triples without proper authorization. This flaw can lead to the removal of critical admin-group membership, potentially locking out administrators and disrupting site functionality. Organizations using YesWiki should prioritize patching to mitigate the risk of unauthorized access and administrative lockout.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples regardless of ownership. Attackers can send an empty filter to the triples delete endpoint to remove the admins-group membership triple, emptying the admin group and causing a site-wide authorization lockout.