Sceawere

Vulnerability Detail

CVE-2026-104441UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Unauthenticated SSRF Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary hosts and ports via the {{valeur}} action's url parameter. Attackers can submit the action through the content parameter of handlers/page/render.php to probe internal HTTP services and read back response content matching fiche markup.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-02T12:17:14.997Z",
  "pubdate": "2026-10-02T12:17:14.997Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a critical Server-Side Request Forgery (SSRF) vulnerability. This vulnerability resides in the application's handling of the {{valeur}} action, allowing unauthenticated remote attackers to coerce the server into performing arbitrary HTTP requests to internal or external destinations. By manipulating the 'url' parameter via the 'content' parameter within 'handlers/page/render.php', an attacker can probe internal network services that are otherwise inaccessible from the public internet. The primary security implication is the potential for information disclosure, as the application reflects response content, provided it conforms to the expected fiche markup. This vulnerability grants attackers the capability to map internal network infrastructure, interact with non-public HTTP-based services, and potentially bypass firewall controls. No authentication or elevated privileges are required for exploitation, significantly lowering the barrier to entry for malicious actors. Given the nature of SSRF, this flaw poses a severe risk to the confidentiality and integrity of internal resources residing within the application's hosting environment.",
  "technicalDetails": "The vulnerability is located in the processing logic of the {{valeur}} markup action, which is utilized by YesWiki to fetch and render content from external URLs. The root cause of this SSRF is an insufficient validation and sanitization process of the user-supplied input provided to the 'url' parameter. Specifically, the 'handlers/page/render.php' component fails to enforce strict allow-lists or perform adequate URL scheme filtering when parsing the content parameter.\nThe exploitation flow begins when an unauthenticated attacker sends a crafted request to 'handlers/page/render.php'. By embedding the '{{valeur url=...}}' directive within the content parameter, an attacker can force the server-side application to initiate a GET request to an arbitrary host and port of the attacker's choosing. Because the application logic does not restrict the target destination to external, trusted domains, the server acts as an open proxy for internal resource discovery.\nUpon receiving the malicious request, the server executes the internal fetch operation. The resulting HTTP response from the targeted resource—be it an internal API, a management console, or an external site—is then processed by the render engine. If the response content aligns with the format expected by the fiche markup, the application reflects this data back to the attacker in the rendered page output. This mechanism effectively allows an attacker to 'read' the responses from internal services that may not have authentication enabled (e.g., local management interfaces, metadata services, or internal databases accessible via HTTP).\nThis vulnerability is particularly dangerous in environments where the YesWiki server is deployed behind a perimeter firewall or within a DMZ. By leveraging the server's network location, the attacker bypasses standard access control lists (ACLs) to reach internal network segments. Successful exploitation facilitates reconnaissance, the potential extraction of sensitive configuration data, or the triggering of actions on internal services that trust requests originating from the YesWiki server's IP address. The vulnerability remains present in all YesWiki versions prior to 4.6.7, requiring no specific user interaction or administrative privileges for successful execution."
}
CVE-2026-104441: YesWiki Unauthenticated SSRF Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere