Impact
YesWiki before version 4.6.7 contains a CSRF weakness in the admintag action that lets an attacker delete tag associations by luring an administrator to click a crafted GET link. The flaw allows the attacker to supply a broad range of tag identifiers, thereby bulk‑deleting tag triples that link content to categories or metadata. The vulnerability is a classic cross‑site request forgery, coded as CWE‑352, and results in integrity loss of the site’s tagging system without affecting confidentiality or granting code execution.
Affected Systems
YesWiki application (vendor YesWiki:yeswiki) – all releases prior to 4.6.7 are vulnerable. Any deployment of YesWiki 4.6.6 or earlier must be considered at risk.
Risk and Exploitability
The CVSS score of 5.3 places it in the moderate range, and the lack of an EPSS score suggests that exploitation probability is uncertain but not negligible. Because it affects only administrators, the impact is localized to those accounts, yet the deletion of tags can break content linking across the entire site. The flaw is not currently represented in CISA’s KEV catalog, so the urgency is lower than a widely exploited vulnerability, but any organisation managing content integrity should treat it as high priority.
OpenCVE Enrichment