← volver
CVE-2025-46549

Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

CVSS 4.3 MEDIUMEPSS 0.5%CWE-79
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 4.3EPSS 0.5%KEV nãoPoC Nuclei simMetasploit Patch
Ciclo de vida
29 abr 2025Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Productos afectados
YesWiki · yeswiki

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →