Sceawere
Vulnerability Detail
CVE-2026-104457UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki Bazar SQL Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into a raw tags.value IN (...) clause. Unauthenticated attackers on default installs can save filtertags markup in a page with a trailing-backslash token that breaks quote parity under MySQL backslash escaping. This lets them inject a five-column UNION subquery to read arbitrary table data such as password hashes.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-10-02T12:17:17.653Z",
"pubdate": "2026-10-02T12:17:17.653Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 contain a critical SQL injection vulnerability within the Bazar plugin's filtertags action.\nThe vulnerability arises from improper handling of user-supplied filterN attribute tokens, which are concatenated into a raw SQL query.\nUnauthenticated attackers can exploit this flaw by embedding specifically crafted markup in a page, allowing them to manipulate the structure of an SQL IN clause.\nSuccessful exploitation enables an attacker to perform unauthorized UNION-based SQL injection, potentially leading to the extraction of sensitive data from the database, including password hashes.\nThe attack is facilitated by MySQL backslash escaping mechanics, where a trailing backslash can break quote parity, effectively allowing the attacker to escape the intended string boundary and inject arbitrary SQL commands.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the YesWiki installation, as it requires no prior authentication or administrative privileges to execute on default configurations.",
"technicalDetails": "The root cause of this vulnerability lies in the improper sanitization and handling of the filterN attribute tokens within the Bazar filtertags action in YesWiki. When the application processes these tokens, it wraps them in quotes and concatenates them directly into an SQL tags.value IN (...) clause without adequate escaping mechanisms or parameterized queries.\nThe exploitation relies on the interaction between the application's string handling and MySQL's backslash escaping behavior. An attacker can craft a payload containing a trailing backslash within the filterN attribute. Because the application wraps this input in single quotes, the trailing backslash escapes the closing quote, causing the SQL parser to misinterpret the query's boundary.\nThe attack flow proceeds as follows: First, the attacker saves malicious filtertags markup on a public-facing or accessible page. When a user or system process triggers the rendering of this page, the Bazar plugin processes the injected filterN attribute. By utilizing the backslash, the attacker breaks the quote parity, effectively terminating the intended string literal prematurely.\nOnce the quote is escaped, the attacker can break out of the original IN clause and append a UNION-based subquery. This subquery is then executed by the underlying MySQL database with the privileges of the database user configured for the YesWiki application.\nThe impact of this injection is severe; the attacker can use the UNION subquery to retrieve information from arbitrary tables within the database. This includes the ability to query table schemas, column names, and sensitive user data such as password hashes. Since this occurs at the database layer, the attacker can effectively bypass application-level access controls.\nThe vulnerability is present in all YesWiki versions before 4.6.7. As the Bazar plugin is a core component, this vulnerability is exposed on default installations. No authentication or elevated privileges are required to inject the malicious markup, making the attack surface broad and accessible to unauthenticated remote attackers."
}