Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-46549

Опубликовано: 29 апр. 2025
Источник: nvd
CVSS3: 4.3
CVSS3: 6.1
EPSS Низкий

Описание

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
Версия до 4.5.4 (исключая)

EPSS

Процентиль: 50%
0.00271
Низкий

4.3 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.3
github
9 месяцев назад

Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting

EPSS

Процентиль: 50%
0.00271
Низкий

4.3 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79