Impact
YesWiki versions before 4.6.7 contain a cross‑site request forgery vulnerability in the autoupdate UpdateAction module that allows an attacker to issue an unprotected GET request with action=delete and a package name. When a logged‑in administrator follows a crafted link, the specified package is deleted, which can remove essential extensions such as bazar and break core site functionality. This flaw is identified as CWE‑352 and results in a loss of service rather than direct code execution.
Affected Systems
The affected product is YesWiki, the popular open‑source wiki engine. All installations using YesWiki versions earlier than 4.6.7 are vulnerable; the specific versions prior to 4.6.7 have been listed as impacted. No further sub‑version details are provided in the advisory.
Risk and Exploitability
The CVSS score is 7.1, indicating a moderate to high severity exploiting this flaw. No EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated administrator to be tricked into visiting a crafted link, so exploitation relies on social engineering and the presence of an active admin session. Given the potential for widespread service disruption, the risk is considered significant for sites that rely on installed extensions.
OpenCVE Enrichment