Impact
YesWiki installations running a version earlier than 4.6.7 are vulnerable to an unauthenticated server‑side request forgery (SSRF) via the {{valeur}} action. By including a crafted content value that references an arbitrary URL, a remote attacker can cause the YesWiki server to fetch data from any host and port reachable from the server. The application returns the fetched data in fiche markup, allowing the attacker to read the response body. This flaw permits disclosure of internal services and can serve as a foothold for further exploitation such as remote code execution.
Affected Systems
All installations of YesWiki with a version before 4.6.7 are affected. The issue is present in every deployment where the {{valeur}} tag is enabled, including community and private instances. Versions 4.6.7 and newer contain the necessary fix.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk. The exploit requires no authentication and can be triggered by any unauthenticated client that can reach the web application. Failure to mitigate can expose internal network traffic and data. Although no EPSS value is published and the vulnerability is not listed in the CISA KEV catalog, the nature of the flaw—unauthenticated SSRF—represents a common attack vector that can be leveraged in broader intrusion campaigns.
OpenCVE Enrichment