Impact
YesWiki on any version prior to 4.6.7 accepts GET requests to the ajaxdeletepage handler that include a jsonp_callback parameter without validating a CSRF token. This flaw allows an attacker to permanently delete a targeted page, its access control lists, links, triples, comments and referrers when a logged‑in administrator or page owner is tricked into visiting a crafted URL. The data lost can be critical to the organization and the removal cannot be undone without a backup.
Affected Systems
The vulnerability affects the YesWiki content management system, specifically all releases before 4.6.7. The product is maintained by the YesWiki community and impacts versions 4.6.6 and older.
Risk and Exploitability
The CVSS score of 7.2 indicates a high impact vulnerability that can be exploited through a CSRF attack vector. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, but the lack of a mitigation token means any authenticated user can be victimized by a simple click‑through phishing link. The risk is significant for sites with active administrators and page owners, and immediate remediation is advised.
OpenCVE Enrichment