CVE-2025-46550

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take over the user’s session. This vulnerability may also allow attackers to deface the website or embed malicious content. This issue has been patched in version 4.5.4.
Configurations

No configuration.

History

29 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 21:15

Updated : 2025-04-29 21:15


NVD link : CVE-2025-46550

Mitre link : CVE-2025-46550

CVE.ORG link : CVE-2025-46550


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')