CyberRota Analysis
AI-GeneratedYesWiki versions prior to 4.6.7 are vulnerable to an authorization bypass in the comments API, allowing authenticated low-privilege users to overwrite any page or comment by manipulating the pagetag field in a POST request. This vulnerability can lead to unauthorized content modification and potential data integrity issues. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments by supplying their own page as the pagetag field. Attackers can send a POST request to the api/comments endpoint targeting a victim tag, bypassing per-page write ACLs to replace content and reparent existing pages or comments.