Impact
YesWiki versions before 4.6.7 contain an access control bypass that lets an unauthenticated attacker read restricted page content. By requesting the XML method of a page that hosts the recentchangesrssplus RSS action, the attacker receives 500‑character excerpts from every recently updated page, including drafts and notes that are normally read‑restricted. This vulnerability exposes confidential information that should be protected by the site’s access controls.
Affected Systems
The affected product is YesWiki from the YesWiki vendor. All installations running a version earlier than 4.6.7 are impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no current widespread exploitation. The likely attack vector is a remote HTTP request to the recentchangesrssplus RSS endpoint, which is available to unauthenticated users. Once triggered, the attacker can extract snippets of any page that has been recently modified, potentially revealing sensitive draft content.
OpenCVE Enrichment