CyberRota Analysis
AI-GeneratedYesWiki versions prior to 4.6.7 are vulnerable to an SQL injection in the Bazar nuagetag action, allowing attackers with page-write access to manipulate SQL queries and extract sensitive data, including password hashes. This high-severity vulnerability poses a significant risk, particularly for installations with default settings that permit unauthenticated access. Organizations using YesWiki should prioritize patching to mitigate potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a nuagetag tag ending in a backslash to break quote parity and inject a UNION subquery, exfiltrating password hashes and arbitrary table data.