Sceawere

Vulnerability Detail

CVE-2026-104451UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki CSRF Revision Restoration Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token validation. Attackers can lure write-capable users into a top-level navigation with the restoreRevisionId parameter, silently overwriting current page content with stale or vandalized revisions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-02T12:17:16.673Z",
  "pubdate": "2026-10-02T12:17:16.673Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability located within the RevisionsHandler component. This security flaw enables unauthorized actors to force authenticated, write-capable users to execute state-changing actions without their consent or knowledge.\nThe vulnerability stems from the improper handling of sensitive operations via GET requests, which lack mandatory CSRF token validation. By crafting a malicious request and luring an authenticated administrative or privileged user to a controlled environment, an attacker can trigger the restoration of obsolete or malicious page revisions.\nThe primary impact is the unauthorized modification of application content, which may result in data loss, the reintroduction of deprecated information, or the silent restoration of previously sanitized malicious payloads. This attack requires the victim to possess write permissions within the YesWiki instance. The exploit does not require the attacker to possess direct access to the application, relying instead on browser-based request forgery. This vulnerability poses a significant risk to the integrity of the wiki’s knowledge base, as it allows attackers to revert legitimate updates and potentially disrupt collaborative workflows.",
  "technicalDetails": "The vulnerability resides in the YesWiki RevisionsHandler, which is responsible for managing and reverting historical page revisions. Analysis indicates that the application fails to enforce CSRF protection for requests intended to commit a revision restoration. Specifically, the implementation utilizes GET requests to process the 'restoreRevisionId' parameter, rendering the sensitive state-changing operation susceptible to unauthorized invocation.\nIn a standard CSRF exploitation scenario against YesWiki, the attack flow initiates when an authenticated user with write access visits an attacker-controlled website or interacts with a crafted link. The attacker embeds a request—either through an HTML image tag, an iframe, or a standard link—that targets the vulnerable RevisionsHandler endpoint with the 'restoreRevisionId' parameter set to the target revision identifier.\nBecause the YesWiki application does not validate a unique, cryptographically strong CSRF token for this specific action, the user's browser automatically appends the relevant session cookies to the forged GET request. Upon receiving the request, the RevisionsHandler interprets it as a legitimate action initiated by the authenticated user. Consequently, the application processes the request, locates the specified 'restoreRevisionId', and overwrites the current live page content with the data associated with that historical revision.\nThe absence of HTTP POST requirement and the lack of server-side origin verification allow for trivial exploitation. This vulnerability affects all YesWiki versions prior to 4.6.7. The technical impact is profound: an attacker can effectively perform a 'rollback' attack, undoing recent legitimate edits. Furthermore, if an attacker previously inserted malicious content or XSS payloads into an older revision, they can use this CSRF vulnerability to silently re-inject that content into the live version of the site without directly interacting with the application's administrative interface. The attack is executed entirely within the context of the victim's authenticated session, bypassing standard access control checks at the network level and operating solely through the victim's legitimate browser session."
}
CVE-2026-104451: YesWiki CSRF Revision Restoration Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere