Sceawere

Vulnerability Detail

CVE-2026-104462UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Bazar SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a nuagetag tag ending in a backslash to break quote parity and inject a UNION subquery, exfiltrating password hashes and arbitrary table data.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-02T12:17:18.467Z",
  "pubdate": "2026-10-02T12:17:18.467Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are affected by a critical SQL injection vulnerability within the Bazar nuagetag action component.\nThis security flaw arises from the improper sanitization and escaping of the user-controlled 'tags' attribute before its concatenation into a raw SQL IN clause.\nConsequently, remote attackers can exploit this weakness to execute arbitrary SQL commands.\nOn default installations of YesWiki, page-write access is unauthenticated, meaning that external, unauthenticated threat actors can leverage this vulnerability without prior credentials.\nBy embedding a malicious nuagetag containing a trailing backslash, an attacker can effectively break quote parity within the constructed database query.\nThis syntactic disruption enables the injection of a UNION subquery, leading to unauthorized access to the database.\nThe risk implication of this vulnerability is severe, as it directly compromises database confidentiality, allowing attackers to exfiltrate sensitive information, including administrative password hashes and arbitrary database table contents.\nSuccessful exploitation can lead to full application compromise.\nOrganizations running affected versions of YesWiki should immediately apply the available security updates to version 4.6.7 or later to mitigate this high-severity risk.",
  "technicalDetails": "The root cause of this vulnerability lies within the input processing logic of the Bazar nuagetag action in YesWiki prior to version 4.6.7.\nSpecifically, the application fails to properly validate and escape the 'tags' attribute before incorporating it into a raw SQL query.\nThe unsafe parameter is directly concatenated into an SQL IN clause, which is structured to filter database records based on tag values.\nTo exploit this vulnerability, an attacker must have page-write access, which is enabled by default for unauthenticated users in standard YesWiki installations.\nThe attack vector involves embedding a specially crafted nuagetag tag on a wiki page.\nThe malicious tag is designed to end with a backslash character.\nWhen the application processes this tag, the backslash acts as an escape character for the closing single quote of the SQL string literal within the database query.\nThis unexpected escaping breaks the quote parity of the SQL statement, causing the database engine to interpret subsequent parts of the query as active SQL commands rather than static string data.\nWith the quote parity broken, the query structure is disrupted, allowing an attacker to append a UNION SELECT subquery to the original database request.\nThis allows the attacker to manipulate the query results returned by the database engine.\nThe injected UNION subquery can be structured to retrieve sensitive records from other database tables, such as the user credentials table containing cryptographic password hashes or other application metadata.\nThe database then processes this manipulated query and returns the unauthorized data payload to the application interface, where it can be harvested by the attacker.\nThe network exposure of this vulnerability is high, as the Bazar nuagetag action can be triggered via standard HTTP requests to the wiki platform.\nThe post-exploitation impact includes complete confidentiality loss of the underlying database, potential privilege escalation via cracked password hashes, and unauthorized access to proprietary or sensitive information stored within the YesWiki instance.\nBecause the injection occurs in the backend database execution context, the vulnerability can bypass traditional application-level access controls once the initial write permission is obtained.\nThis enables lateral movement within the hosting environment if the database server shares credentials or access with other internal systems."
}
CVE-2026-104462: YesWiki Bazar SQL Injection (HIGH Severity, CVSS: 7.5) | Sceawere