Impact
YesWiki versions before 4.6.7 allow unauthenticated attackers to inject SQL through the filtertags action. The vulnerability occurs because tokens from the filterN attribute are embedded directly inside a quotes‑wrapped IN clause without proper escaping, and a trailing backslash can toggle quote parity under MySQL’s backslash escaping. An attacker can then craft a UNION subquery that returns data from arbitrary tables, including password hashes, thereby compromising confidentiality and potentially enabling further exploitation.
Affected Systems
The affected product is YesWiki, all releases prior to 4.6.7. Attackers can target standard default installations that expose the Bazar filtertags functionality.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, and while the EPSS score is not available, the known exploit potential is significant. The vulnerability is not currently listed in CISA KEV. Attackers need no authentication on a default install and can execute the injection via a crafted page that stores malicious markup.
OpenCVE Enrichment