CyberRota Analysis
AI-GeneratedYesWiki versions prior to 4.6.7 are vulnerable to an authentication bypass in the ActivityPub inbox, allowing unauthenticated attackers to exploit this flaw using any ActivityPub keypair. This vulnerability enables them to send signed Delete or Update activities that can delete or overwrite other actors' federated entries, posing a significant risk to data integrity. Organizations using YesWiki should prioritize patching this vulnerability to prevent unauthorized data manipulation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. Unauthenticated attackers with any ActivityPub keypair can send signed Delete or Update activities referencing a mirrored entry's sourceUrl to delete or overwrite other actors' federated entries.