CyberRota Analysis
AI-GeneratedYesWiki versions prior to 4.6.7 are vulnerable to a cross-site request forgery (CSRF) flaw in the autoupdate UpdateAction, enabling attackers to execute unprotected GET requests that can delete installed packages. This vulnerability can be exploited by tricking a logged-in administrator into clicking a malicious link, potentially disrupting core site functionality by removing critical extensions. Organizations using YesWiki should prioritize patching to mitigate the risk of unauthorized package deletions and maintain site integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link with action=delete and a package parameter to remove extensions like bazar, breaking core site functionality.