Sceawere
Vulnerability Detail
CVE-2026-104471UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
YesWiki Unrestricted File Upload RCE
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 11h ago
- Vendor
- YesWiki
- Product
- yeswiki
- Attack Type
- Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV import preview. Attackers can import a CSV whose file or image field references a remote .php URL, which is saved without extension checks and executed as server-side code.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T12:17:20.037Z",
"pubdate": "2026-10-02T12:17:20.037Z",
"executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to an unrestricted file upload vulnerability leading to Remote Code Execution (RCE).\nThe vulnerability resides in the Bazar CSV import preview feature, which improperly validates file references during the import process.\nAn authenticated user with administrative privileges can supply a malicious CSV file containing references to remote URLs pointing to arbitrary server-side code (PHP).\nThe application saves these remote files into the web-accessible 'files/' directory without performing adequate extension or content validation, allowing the web server to execute the uploaded script.\nThe primary risk is a total system compromise, as successful exploitation enables an attacker to execute arbitrary PHP code on the server, facilitating unauthorized data access, system modification, or persistence.\nExploitation requires administrative authentication and the ability to trigger the Bazar CSV import function.",
"technicalDetails": "The vulnerability is an unrestricted file upload flaw occurring within the Bazar component of YesWiki. The root cause is a failure to sanitize or validate the source of files imported via the CSV import preview mechanism.\nDuring the CSV import process, the application parses the provided file to extract data fields. If the CSV contains fields configured as file or image types, the application attempts to retrieve the associated content. The vulnerability arises because the import logic does not verify that the referenced resource originates from a trusted source, nor does it enforce strict file extension restrictions before writing the retrieved content to the local filesystem.\nThe exploit flow follows these steps: 1. The attacker creates a malicious CSV file where specific fields (designed for file or image uploads) contain URLs pointing to a remote server controlled by the attacker. 2. This remote server hosts a malicious PHP script disguised or referenced as a resource. 3. The attacker, authenticated as an administrator, initiates the Bazar CSV import process and uploads the crafted CSV. 4. YesWiki parses the CSV, identifies the malicious URL, and fetches the remote payload. 5. The application saves the retrieved remote content directly into the 'files/' directory, which is configured to be web-accessible. 6. Because the application fails to validate the file extension, the attacker can ensure the file is saved with a .php extension or is otherwise executable by the web server's PHP interpreter.\nOnce the file is successfully saved in the 'files/' directory, the attacker can execute the arbitrary code by requesting the file directly via its URL (e.g., /files/malicious_script.php). This results in full execution of the payload within the context of the web server process.\nThe vulnerability is present in versions of YesWiki prior to 4.6.7. Successful exploitation requires administrative-level privileges, as the Bazar CSV import functionality is restricted to authorized users. Post-exploitation impact is severe, typically resulting in full compromise of the underlying server infrastructure."
}