Impact
YesWiki versions prior to 4.6.7 contain a cross‑site request forgery flaw in the RevisionsHandler that allows an attacker to force a user to send a GET request with a restoreRevisionId parameter. The request bypasses CSRF token validation and silently restores a previously saved page revision, overwriting the current page contents. This flaw permits stealthy content modification, compromising data integrity on the site.
Affected Systems
The vulnerability affects the YesWiki CMS when running any version earlier than 4.6.7. Administrators using older releases should review their deployment, as the affected component is the RevisionsHandler module within the YesWiki codebase.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and no EPSS score is available for this entry. Although the vulnerability is not listed in the CISA KEV catalog, the CSRF nature of the flaw means that exploitation requires a social‑engineering step, such as luring a write‑capable user onto a malicious link or navigation item. Once a user follows the crafted link, the page would be overwritten with an older revision without notification.
OpenCVE Enrichment