Description
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments on GET requests without validating a CSRF token. Attackers can lure a logged-in page owner or administrator into a top-level GET navigation with do=del, erase, or emptytrash, deleting or permanently purging the page's attachments.
Published: 2026-10-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Data Loss
Action: Patch promptly
AI Analysis

Impact

YesWiki released a cross‑site request forgery flaw in the filemanager page handler that allows an attacker to trigger a GET request without a CSRF token and delete all attachments on a page. By using the parameters do=del, erase, or emptytrash, a logged‑in page owner or administrator can be tricked into navigating to a URL that permanently removes or clears the page’s attachment store. The vulnerability compromises the integrity of user‑created content, leading to loss or irreversible deletion of media and documents, but does not expose code execution or sensitive data.

Affected Systems

YesWiki versions prior to 4.6.7 are affected. The flaw exists in the YesWiki product as distributed by the YesWiki:yeswiki vendor. No further vendor or product ranges were specified beyond the model version threshold.

Risk and Exploitability

The CVSS score of 5.3 places the vulnerability in the medium severity range. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. The likelihood of exploitation requires the attacker to persuade a legitimate logged‑in user or administrator to visit a malicious link that appends the delete parameters. While the attack vector is indirect, the potential for significant data loss makes the risk tangible for organizations that rely on the attachments for business operations.

Generated by OpenCVE AI on October 2, 2026 at 13:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official YesWiki 4.6.7 update or later to patch the CSRF flaw
  • Restrict or monitor access to the ’do=del’, ’erase’, and ’emptytrash’ parameters by implementing user‑level permissions or post‑redirect patterns
  • Implement web application firewall rules to block unsolicited GET requests containing the delete parameters

Generated by OpenCVE AI on October 2, 2026 at 13:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments on GET requests without validating a CSRF token. Attackers can lure a logged-in page owner or administrator into a top-level GET navigation with do=del, erase, or emptytrash, deleting or permanently purging the page's attachments.
Title YesWiki before 4.6.7 CSRF Attachment Deletion via filemanager Handler
First Time appeared Yeswiki
Yeswiki yeswiki
Weaknesses CWE-352
CPEs cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Vendors & Products Yeswiki
Yeswiki yeswiki
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:02:31.301Z

Reserved: 2026-10-02T00:53:58.504Z

Link: CVE-2026-104452

cve-icon Vulnrichment

Updated: 2026-10-02T14:02:27.583Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:16.840

Modified: 2026-10-02T12:17:16.957

Link: CVE-2026-104452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:15:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)