Impact
YesWiki versions before 4.6.7 contain a stored cross‑site scripting flaw in the Bazar valeur action. Page editors can supply a remote URL that returns BAZ_fiche_titre markup with an image tag containing an onerror handler or other JavaScript. When the page is rendered, the unescaped HTML is inserted directly into the page, allowing arbitrary script execution in the browser of any user who views the page. This weakness is a classic input validation failure (CWE‑79) and based on the description, it is inferred that attackers could use the stored XSS to hijack sessions, steal credentials, or deliver malware through the victim’s browser.
Affected Systems
Any installation of YesWiki running a version older than 4.6.7 that includes the Bazar plugin is affected. Attackers may target the Bazar valeur action endpoint exposed under tools/bazar/actions/valeur.php.
Risk and Exploitability
The vulnerability scores a CVSS of 5.1, indicating medium severity, and no EPSS data is currently available. It is not listed in CISA’s KEV catalog. Exploitation requires the attacker to have editing privileges or the ability to trigger the Bazar action with a crafted remote URL, so the likely attack vector is limited to trusted users or compromised accounts. Nevertheless, the stored XSS payload will execute for every user who views the affected page, potentially exposing sensitive data or facilitating further attacks.
OpenCVE Enrichment