Sceawere

Vulnerability Detail

CVE-2026-104470UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki SSRF and XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
11h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a server-side request forgery vulnerability in the Bazar valeur action that allows page editors to make the server fetch arbitrary URLs. Attackers can supply loopback or internal URLs in the url parameter to probe internal services and inject unescaped remote HTML that executes scripts in viewers' browsers.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-10-02T12:17:19.870Z",
  "pubdate": "2026-10-02T12:17:19.870Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a critical Server-Side Request Forgery (SSRF) vulnerability residing within the 'Bazar valeur' action component.\nThis vulnerability permits authenticated users with page editing privileges to manipulate the 'url' parameter, forcing the host server to initiate arbitrary HTTP requests.\nThe flaw carries significant security implications, as it allows attackers to probe internal network services, bypass firewall restrictions, and conduct internal reconnaissance.\nFurthermore, the vulnerability enables the injection of unescaped HTML content, facilitating Cross-Site Scripting (XSS) attacks that execute arbitrary scripts within the context of the viewer's browser session.\nThe risk is exacerbated by the ability to interact with loopback interfaces and private network resources, potentially leading to unauthorized data exfiltration or credential theft.\nExploitation requires the attacker to possess sufficient privileges to edit pages in YesWiki, after which they can leverage the server's trust relationship to perform malicious requests on their behalf.",
  "technicalDetails": "The vulnerability is localized within the 'Bazar valeur' action handler of YesWiki, which fails to adequately sanitize or validate the user-supplied 'url' parameter before passing it to the server's internal request mechanism.\nThe root cause is an improper input validation flaw where the application functions as a confused deputy, executing HTTP requests to destinations specified by the user without applying an allow-list or performing network segment filtering.\nThe attack flow commences when a malicious actor, authenticated with page editing permissions, crafts a specific request targeting the 'Bazar valeur' action. By manipulating the 'url' parameter, the attacker can specify internal IP addresses (e.g., 127.0.0.1) or internal network hostnames.\nWhen the server processes this request, it attempts to fetch the content from the attacker-specified URL. If the server is configured to allow requests to loopback addresses, the attacker can interact with local services that are not exposed to the public internet.\nBeyond internal reconnaissance, the vulnerability supports the injection of arbitrary, unescaped HTML content. When the server fetches the remote content, it reflects this data back to viewers of the page. If the remote URL provides malicious HTML containing script tags, this payload is rendered directly in the victim's browser.\nThis post-exploitation impact allows for the execution of arbitrary JavaScript, leading to potential session hijacking, cookie theft, or unauthorized actions performed in the name of the victim.\nThe technical requirements for successful exploitation involve having edit access to the Wiki. The attack is effective across all versions prior to 4.6.7, as the underlying code responsible for the 'Bazar valeur' action lacks the necessary security controls to constrain outbound traffic or sanitize the reflection of fetched content.\nSuccessful exploitation bypasses network-level defenses such as firewalls, as the requests originate from the trusted application server itself, granting the attacker a foothold to enumerate internal APIs and service endpoints."
}
CVE-2026-104470: YesWiki SSRF and XSS Vulnerability (HIGH Severity, CVSS: 7.4) | Sceawere