PT-2026-42810 · Yeswiki · Yeswiki
CVE-2026-46670
·
Published
2026-05-22
·
Updated
2026-08-11
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
YesWiki versions prior to 4.6.4
Description
An unauthenticated SQL injection exists in the Bazar form-import path within the
FormManager::create() function. This flaw allows an unauthenticated visitor of a default installation to inject arbitrary SQL into an INSERT statement. An attacker can exploit this to read the entire database, including sensitive user credentials such as yeswiki users.password hashes. The issue is caused by the unquoted concatenation of the bn id nature variable into the INSERT VALUES list.Recommendations
Update YesWiki to version 4.6.4.
As a temporary mitigation, restrict access to the Bazar form-import functionality until the update is applied.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yeswiki