Impact
YesWiki before 4.6.7 has an authentication bypass in the contact mail AJAX handler that lets unauthenticated attackers send email through the wiki's SMTP server, allowing spam or phishing. The flaw is a CWE-306 Authentication Bypass, and it requires no parameters in the POST request. Attackers can supply arbitrary recipient, sender, subject, and body. The vulnerability permits the wiki to act as an open mail relay without access control, which can be abused to deliver large volumes of spam, phishing, or other malicious content. The impact is confined to the mail functionality of the affected instance, with a CVSS score of 6.9 reflecting moderate severity. The flaw is not listed in the CISA KEV catalog and EPSS data is not available, but the straightforward unauthenticated attack path makes it exploitable.
Affected Systems
All YesWiki installations running versions earlier than 4.6.7 are vulnerable, as documented by the YesWiki security advisory.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk, with no EPSS data and not listed in the KEV catalog. Attackers only need to send a POST request to the known AJAX endpoint without authentication, making exploitation trivial if the wiki is publicly accessible.
OpenCVE Enrichment