Impact
YesWiki versions prior to 4.6.7 have a flaw in the LostPasswordAction.php script that exposes whether an email address is registered. By submitting any email address to the password‑recovery URL, attackers receive different responses, allowing them to enumerate valid user accounts without authentication. This discovery can facilitate targeted phishing or password‑spraying attacks against those accounts. The weakness is a denial of information confidentiality (CWE‑204).
Affected Systems
All deployments of YesWiki running any release before version 4.6.7 are affected. The enumerated vulnerability exists in the yeswiki product, as identified by the CPE cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*.*
Risk and Exploitability
The CVSS base score is 7.1, indicating a high severity, but the EPSS score is not available, and it is not listed in the CISA KEV catalog. Attackers can trigger the vulnerability simply by sending unauthenticated HTTP requests to the lost‑password page, which lacks rate‑limiting or additional checks. Given the lack of defensive controls, the exploitation likelihood is fairly high for an attacker who knows or can guess a target domain. If the enumeration is confirmed, it may lead to credential‑guessing campaigns or phishing, affecting the confidentiality of user accounts and potentially causing broader compromise if credentials are reused.
OpenCVE Enrichment