Sceawere

Vulnerability Detail

CVE-2026-105224UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

YesWiki Bazar Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
4h ago
Vendor
YesWiki
Product
yeswiki
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attackers can point tools/bazar/actions/valeur.php at a controlled server returning BAZ_fiche_titre markup with an img onerror handler, executing script in every viewer's browser.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-04T16:16:30.470Z",
  "pubdate": "2026-10-04T16:16:30.470Z",
  "executiveSummary": "YesWiki versions prior to 4.6.7 are susceptible to a stored Cross-Site Scripting (XSS) vulnerability located within the 'Bazar' module's 'valeur' action. This flaw arises from the improper handling of externally fetched data, allowing unauthorized users to inject and execute arbitrary JavaScript code in the browsers of visitors.\nThe vulnerability is triggered via the 'valeur.php' script, which retrieves content from remote URLs without performing adequate sanitization or output encoding. An attacker capable of influencing the remote content source can inject malicious payloads, such as 'img' tags with 'onerror' event handlers, into the 'BAZ_fiche_titre' markup.\nThe impact includes the execution of malicious scripts within the context of the user's session, which may lead to unauthorized data access, session hijacking, or defacement. Exploitation requires the attacker to be a page editor who can specify a remote source for the Bazar action. Given that this vulnerability facilitates persistent script execution, it poses a significant risk to site integrity and visitor security. Immediate updates to the core software are recommended to mitigate the risks associated with unvalidated remote data processing.",
  "technicalDetails": "The vulnerability resides in the 'tools/bazar/actions/valeur.php' file of the YesWiki application. The root cause is the insecure implementation of a remote data fetching mechanism that processes data returned by a user-specified URL. Specifically, the application parses the fetched content for 'BAZ_fiche_titre' markup and renders the resulting data directly into the DOM without sufficient sanitization or context-aware output encoding.\nThe attack flow commences when an authenticated attacker with sufficient privileges to edit pages interacts with the 'Bazar' module. By configuring the 'valeur.php' action to point to a remote server under the attacker's control, the attacker directs the application to ingest malformed content. The attacker's server responds with a payload disguised as 'BAZ_fiche_titre' markup, incorporating an HTML element—typically an 'img' tag—containing an 'onerror' attribute configured to execute a JavaScript payload.\nWhen a legitimate user navigates to the affected page, the server-side code renders the stored malicious string. The client-side browser interprets the 'img' tag and, due to the intentional absence of a valid source attribute, triggers the 'onerror' event handler. This results in the execution of the injected JavaScript code within the security context of the victim's session.\nBecause the payload is rendered by the application, the malicious script operates with the same origin permissions as the YesWiki instance. This enables the attacker to perform actions on behalf of the user, such as exfiltrating sensitive session cookies (if 'HttpOnly' flags are absent), modifying DOM content, or performing unauthorized administrative actions if the victim holds elevated privileges. The vulnerability is categorized as a stored XSS because the malicious content is fetched and rendered whenever the page is accessed, creating a persistent threat vector for any user viewing the page. This vulnerability highlights the risks inherent in trusting remote content sources and the critical necessity for strict server-side validation and context-sensitive output encoding, even when dealing with modules intended for dynamic content aggregation."
}
CVE-2026-105224: YesWiki Bazar Stored XSS Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere