Sceawere

Vulnerability Detail

CVE-2026-104447UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki CSRF Package Deletion Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers can lure a logged-in administrator to a crafted link with action=delete and a package parameter to remove extensions like bazar, breaking core site functionality.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-02T12:17:15.990Z",
  "pubdate": "2026-10-02T12:17:15.990Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability residing within the autoupdate UpdateAction component. This security flaw enables a remote, unauthenticated attacker to induce a logged-in administrator to execute unauthorized administrative operations. By coercing the victim into accessing a maliciously crafted URI, an attacker can trigger the deletion of installed system packages. Successful exploitation allows for the removal of critical extensions, such as the 'bazar' package, leading to an immediate denial-of-service (DoS) condition or significant degradation of core site functionality. The vulnerability stems from the application's failure to enforce anti-CSRF tokens or implement proper request method validation for sensitive administrative actions initiated via GET requests. The risk is considered high due to the potential for site destabilization and the ease with which an attacker can trick an administrative user into visiting a malicious link.",
  "technicalDetails": "The vulnerability is located within the autoupdate functionality of YesWiki, specifically handled by the UpdateAction component. The root cause is the improper handling of state-changing administrative requests via HTTP GET methods, which lack CSRF protection mechanisms such as anti-forgery tokens or SameSite cookie attributes. Because the application processes the deletion of extensions based on parameters passed directly in the URL without requiring a secondary verification or a POST-based request with a cryptographic challenge, it becomes vulnerable to CSRF.\nThe exploitation flow begins when an authenticated administrator visits an attacker-controlled web resource or is lured to a crafted hyperlink. The attacker crafts a request to the YesWiki installation targeting the 'action=delete' parameter within the 'UpdateAction' controller. By including the 'package' parameter, the attacker specifies the target extension to be removed. When the victim's browser executes this request, the web application parses the administrative session cookies, recognizes the victim as an administrator, and processes the deletion command as if it were an intentional administrative action.\nSpecifically, the 'UpdateAction' fails to distinguish between a legitimate request originated from the administrative interface and a cross-origin request initiated by an attacker. Since the vulnerability is triggered via a GET request, it can be seamlessly embedded into an HTML <img> tag, a hidden <iframe>, or a redirect, facilitating invisible execution without user interaction beyond clicking a link or loading a malicious page. The impact of this exploit is severe, as the deletion of core packages like 'bazar' can render the CMS unusable or lead to data loss depending on the dependency chain of the removed extension. The vulnerability exists in all YesWiki versions prior to 4.6.7. Exploitation requires the victim to have an active administrative session, making this a classic session-dependent CSRF attack. There is no requirement for the attacker to have direct access to the server, as the malicious actions are performed under the authority of the logged-in administrator's browser context."
}
CVE-2026-104447: YesWiki CSRF Package Deletion Vulnerability (HIGH Severity, CVSS: 7.1) | Sceawere