Impact
YesWiki versions earlier than 4.6.7 contain a missing authorization flaw in the listpagestag and includepages actions of the tags tool. The flaw allows unauthenticated or unprivileged users to embed these actions with a chosen tag or page name, causing the system to titles without applying the normal read‑ACL filters. The result is a disclosure of the names and titles of pages that are otherwise protected by access control, exposing sensitive page names and potential content identifiers.
Affected Systems
Any installation of YesWiki running a version prior to 4.6.7 is vulnerable. The affected components are the listpagestag and includepages actions within the tags tool. All users, including those with no prior authentication or with low privileges, can trigger the vulnerability by submitting content that includes the vulnerable tags.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating high severity. No EPSS score is available, which offers no explicit exploitation probability, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is through normal HTTP requests to the site where an attacker can embed the vulnerable tags, potentially from any web browser or automated script. Because the flaw bypasses read‑ACL checks, a successful exploit can reveal internal page names and titles to anyone who can submit or view the affected content. The impact is a breach of confidentiality for protected page metadata, and the risk is elevated if sensitive information is inferred from page names or titles.
OpenCVE Enrichment