Sceawere

Vulnerability Detail

CVE-2026-104461UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Bazar Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so SVG files are stored verbatim and served inline as image/svg+xml. Authenticated users can submit entries via POST /api/entries/{formId} with SVG files containing script that executes in the wiki origin when the file is opened, enabling administrator session or account compromise.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-02T12:17:18.303Z",
  "pubdate": "2026-10-02T12:17:18.303Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a stored Cross-Site Scripting (XSS) vulnerability located within the Bazar FileField component.\nThe vulnerability originates from improper input validation during file uploads, specifically concerning the handling of Scalable Vector Graphics (SVG) files.\nBy failing to invoke the HtmlPurifierService::cleanFile function, the application allows the storage and subsequent inline rendering of malicious SVG content.\nAn authenticated attacker can leverage this flaw to inject arbitrary JavaScript, which executes within the context of the wiki's origin when the file is accessed.\nThe primary impact includes potential session hijacking, unauthorized administrative actions, and full account compromise, posing a significant risk to the integrity and confidentiality of the YesWiki installation.\nExploitation requires the attacker to have an authenticated session to interact with the API endpoints.",
  "technicalDetails": "The vulnerability resides in the Bazar FileField implementation within YesWiki, which acts as a file upload handler for entry submissions. The application's security mechanism for file uploads is restricted solely to a rudimentary file extension validation check, which fails to inspect the underlying content or structure of the uploaded files.\nThe core issue stems from the omission of the HtmlPurifierService::cleanFile function in the file upload processing pipeline. In modern web environments, SVG files are XML-based documents that can contain embedded scripts via <script> tags or event handlers within elements. Because the system fails to sanitize these files, malicious SVG payloads are saved to the server and served with the image/svg+xml MIME type.\nThe attack vector involves a POST request directed to /api/entries/{formId}. An authenticated attacker can upload a crafted SVG file containing embedded malicious JavaScript. When an administrator or another user views the uploaded file, the browser interprets the content as an SVG document and executes the embedded script in the security context of the wiki's origin.\nBecause the execution occurs within the wiki's origin, the script gains access to sensitive data, including session cookies, local storage, and the ability to perform actions on behalf of the victim. If an administrator views the file, the attacker may be able to escalate privileges or modify site configuration, leading to full site compromise.\nThe vulnerability is persistent, meaning the malicious payload remains on the server until manually removed, and it can be triggered repeatedly by any user who navigates to the URL associated with the uploaded file. This mechanism effectively bypasses standard web application security controls that rely on simple extension filtering."
}
CVE-2026-104461: YesWiki Bazar Stored XSS (MEDIUM Severity, CVSS: 5.4) | Sceawere