CyberRota Analysis
AI-GeneratedYesWiki versions prior to 4.6.7 are vulnerable to an SQL injection in the Bazar filtertags action, allowing unauthenticated attackers to manipulate the filterN attribute and execute arbitrary SQL queries. This vulnerability can lead to the exposure of sensitive data, including password hashes, from the database. Organizations using YesWiki should prioritize patching this vulnerability to mitigate the risk of data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash token that breaks quote parity under MySQL backslash escaping. This lets them inject a five-column UNION subquery to read arbitrary table data such as password hashes.