Beveiligingsadvies

CVE-2025-46349

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-04-29 17:11:10
Laatst bijgewerkt 2025-04-29 18:01:20
Toegewezen door GitHub_M
CVSS-score 7.6
Status PUBLISHED

Beschrijving

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform arbitrary actions. This issue has been patched in version 4.5.4.