Impact
YesWiki versions prior to 4.6.7 allow an attacker to supply arbitrary URL references in the syndication action that is processed by the render handler’s content parameter. The vulnerable code causes the server to perform an internal HTTP request to the supplied URL, exposing internal hosts and services. Successful exploitation can lead the attacker to read arbitrary network resources, and to download feed enclosures directly into the site’s files directory, potentially writing malicious files to the server. The impact is a breach of confidentiality and integrity on the affected system, without requiring any user authentication. The weakness aligns with CWE‑918, Server‑Side Request Forgery.
Affected Systems
Affected by the YesWiki content management system; any installation of YesWiki prior to version 4.6.7 is vulnerable. The product is identified by cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*.
Risk and Exploitability
The CVSS base score of 6.9 indicates a medium severity for this vulnerability. No EPSS score information is available, so the relative exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been widely observed in the wild. Since it requires only a crafted request to the public render endpoint and no authentication, attackers can trigger the SSRF from any network with access to the server. Without protective network or application controls, the attack can reach internal resources, read sensitive data, or write files to the web‑root.
OpenCVE Enrichment