Impact
YesWiki 4.x before 4.6.7 contains a blind server‑side request forgery in the /api/entries/bazarlist endpoint. By supplying crafted values to the idtypeannonce parameter, an unauthenticated attacker can force the application to fetch arbitrary URLs. Because the input validation always accepts any string, the attacker can target internal addresses and retrieve data from intranet services or metadata endpoints, thereby bypassing network isolation.
Affected Systems
All installations of YesWiki running versions earlier than 4.6.7 are affected. The vulnerability exists in the YesWiki application (yeswiki:yeswiki). No specific sub‑product or module is singled out beyond the core API.
Risk and Exploitability
The flaw carries a CVSS score of 6.9, indicating moderate severity. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The exploit path is straightforward: an unauthenticated HTTP request to /api/entries/bazarlist with a manipulated idtypeannonce value. Because the application does not impose authentication or URL filtering, an attacker can probe any internal network resource reachable from the server, including cloud metadata services.
OpenCVE Enrichment