Impact
YesWiki released a cross‑site request forgery flaw in the filemanager page handler that allows an attacker to trigger a GET request without a CSRF token and delete all attachments on a page. By using the parameters do=del, erase, or emptytrash, a logged‑in page owner or administrator can be tricked into navigating to a URL that permanently removes or clears the page’s attachment store. The vulnerability compromises the integrity of user‑created content, leading to loss or irreversible deletion of media and documents, but does not expose code execution or sensitive data.
Affected Systems
YesWiki versions prior to 4.6.7 are affected. The flaw exists in the YesWiki product as distributed by the YesWiki:yeswiki vendor. No further vendor or product ranges were specified beyond the model version threshold.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium severity range. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. The likelihood of exploitation requires the attacker to persuade a legitimate logged‑in user or administrator to visit a malicious link that appends the delete parameters. While the attack vector is indirect, the potential for significant data loss makes the risk tangible for organizations that rely on the attachments for business operations.
OpenCVE Enrichment