Impact
YesWiki versions prior to 4.6.7 contain an authorization bypass flaw in the comments API editComment route. An authenticated user with low privileges can supply a custom pagetag value when posting to the api/comments endpoint, causing the request to target the specified page instead of the intended comment. This allows the attacker to overwrite arbitrary pages or comments and to reparent existing pages or comments, effectively circumventing the normal per-page write access controls and compromising content integrity.
Affected Systems
The vulnerability affects YesWiki installations identified as "yeswiki:yeswiki" and applies to all releases before 4.6.7. No additional product or version details are provided beyond the base packaging prior to the 4.6.7 release.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity but not critical. EPSS is currently not available, so the current exploitation probability cannot be quantified. The issue is not listed in the CISA KEV catalog. The likely attack vector is the public Comments API; an attacker who is already authenticated can trigger the exploit by sending a POST request to /api/comments with a manipulated pagetag. The exploit requires user credentials but grants privileges that exceed the intended access level.
OpenCVE Enrichment