Impact
This vulnerability in YesWiki versions prior to 4.6.7 allows an unauthenticated attacker to overwrite any existing wiki page, including those protected by write ACLs, by submitting a crafted entry through the Bazar module. The attacker controls the id_fiche field and can match it to an existing page slug, resulting in the page body being replaced with attacker-supplied content. This represents a critical integrity violation, as it enables mass defacement, unauthorized content injection, and permanent loss of legitimate wiki information. The weakness is a permission check failure (CWE‑639).
Affected Systems
YesWiki installations using the YesWiki application, specifically versions older than 4.6.7. Any deployment that has not yet applied the 4.6.7 update is vulnerable.
Risk and Exploitability
The CVSS score of 8.3 classifies the issue as High severity. EPSS information is not available, so exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote unauthenticated web request to the Bazar entry-creation endpoint, where the attacker can supply a crafted id_fiche parameter. Based on the description, it is inferred that an attacker simply needs network access to the web application to exploit this flaw.
OpenCVE Enrichment