Sceawere
Vulnerability Detail
CVE-2026-104453UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki Cross-Site Request Forgery
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Cross-Site Request Forgery (CSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted GET links. Attackers can supply a wide id range in the delete_tag parameter via top-level navigation, carrying the SameSite=Lax admin cookie, to bulk-delete tag triples.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-02T12:17:17.003Z",
"pubdate": "2026-10-02T12:17:17.003Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability located within the 'admintag' action. The vulnerability allows an unauthenticated remote attacker to perform unauthorized administrative operations by inducing an authenticated administrator to interact with a malicious or crafted URL.\nThe vulnerability stems from the application's failure to enforce sufficient state-changing protection mechanisms, such as anti-CSRF tokens, for critical administrative actions. Consequently, an attacker can manipulate the system to execute bulk-deletion of tag associations.\nThe impact is significant, as the vulnerability facilitates the destruction of site metadata and organizational structures without the victim's explicit consent. The attack requires the victim to have an active administrative session and relies on the browser's default handling of cookies, specifically in environments where SameSite=Lax cookie policies are present. The risk level is elevated because the exploit requires no prior authentication for the attacker, but it is contingent upon social engineering or malicious content delivery to an active administrator.",
"technicalDetails": "The vulnerability resides in the 'admintag' action handler within YesWiki versions before 4.6.7. This component processes administrative requests related to tag management. The root cause is the reliance on predictable GET requests for state-changing operations, combined with the absence of a per-request cryptographically secure token, such as a CSRF token, to validate the integrity and intent of the request.\nIn the vulnerable implementation, the 'delete_tag' parameter accepts an integer or a range of identifiers to remove specific tag triples from the database. Because the application logic fails to distinguish between legitimate administrative intent and forged requests triggered by third-party sites, the server honors these requests as long as the user's session remains active.\nThe attack flow proceeds as follows: First, the attacker crafts a malicious URI that targets the 'admintag' action, specifying a broad range of identifiers within the 'delete_tag' parameter to maximize impact. Second, the attacker lures an authenticated administrator into navigating to this URL. This can be achieved through techniques such as embedding the link in an <img> tag, a hidden iframe, or a standard hyperlink on a third-party domain controlled by the attacker.\nUpon the administrator's navigation, the victim's browser automatically appends the administrative session cookie to the request. Since modern browsers often default to SameSite=Lax, and top-level navigation (like standard page visits) is generally permitted under this cookie policy, the request reaches the YesWiki backend with valid session credentials.\nThe backend, lacking secondary verification, processes the delete operation and executes the database modification. This enables a bulk-deletion scenario where an attacker can systematically purge tag triples associated with the wiki content. This action does not require the attacker to know the current CSRF state, as the server does not enforce one for this endpoint. The post-exploitation result is a significant loss of content categorization and metadata, which may necessitate manual restoration from backups or result in permanent disruption of site information architecture."
}