Описание
YesWiki has Authenticated SQL Injection via ReactionManager
Summary
YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id} URL path parameters. The parameters are concatenated directly into a SQL LIKE clause without escaping or parameterization.
This is a sibling of CVE-2026-46670 (unauthenticated SQLi in FormManager::create()). Both share the same root cause — raw string concatenation into SQL queries — but exist in different components.
Root Cause
includes/controllers/ApiController.php line 726:
ACL "+" = any authenticated user. Parameters flow into ReactionManager::deleteUserReaction() → TripleStore::delete() with raw string concatenation into SQL LIKE clause (line 356).
The if branch (lines 340-354) properly uses $this->dbService->escape(). The else branch does not — the developer applied escaping to one code path but not the other.
PoC
Time-based blind variant via {id} parameter for data exfiltration.
Impact
Full database read/write. Any self-registered user can extract yeswiki_users password hashes and emails.
Suggested Fix
Apply $this->dbService->escape() to all parameters in the else branch, matching the if branch pattern. Also audit all TripleStore::delete() callers that pass $extraSQL.
Credits
Kai Aizen / SnailSploit
Пакеты
yeswiki/yeswiki
< 4.6.6
4.6.6
Связанные уязвимости
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id} URL path parameters. The parameters are concatenated directly into a SQL LIKE clause without escaping or parameterization. This issue has been patched in version 4.6.6.