Impact
The flaw resides in the pointimage action of YesWiki versions earlier than 4.6.7. It is a missing authorization bug that allows anyone to POST content to any page that displays the {{pointimage}} macro, bypassing write ACL checks. Because the content is stored directly as raw HTML or JavaScript, the attacker can insert malicious code that will run in the browsers of every viewer, including administrators, when the page is rendered. The vulnerability is a Stored Cross‑Site Scripting flaw, which can lead to session hijacking, defacement, or arbitrary script execution. This is aligned with the Common Weakness Enumeration CWE‑79.
Affected Systems
YesWiki software from all releases before version 4.6.7 is affected. This includes all public deployments running YesWiki 4.6.0 through 4.6.6 and earlier. The issue is specific to the pointimage action located in tools/attach/actions/pointimage.php.
Risk and Exploitability
With a CVSS score of 8.2, this vulnerability is classified as High severity. The exploit requires only unauthenticated HTTP POST requests, meaning any attacker can trigger it without credentials. EPSS data is not available, but the lack of authentication prerequisites and the ability to affect all browsing users indicate a substantial likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, but its high severity and broad impact warrant immediate attention.
OpenCVE Enrichment