vendor:
YesWiki
by:
Al Baradi Joy
7.1
CVSS
HIGH
Unauthenticated Path Traversal (LFI)
22
CWE
Product Name: YesWiki
Affected Version From: < 4.5.2
Affected Version To: 4.5.2001
Patch Exists: YES
Related CWE: CVE-2025-31131
CPE: a:yeswiki_project:yeswiki:4.5.1
Platforms Tested: Ubuntu 22.04
2025
YesWiki Unauthenticated Path Traversal
YesWiki before 4.5.2 allows unauthenticated path traversal via the 'squelette' parameter. An attacker can exploit this to read arbitrary files on the server, like /etc/passwd.
Mitigation:
Upgrade to version 4.5.2 or higher to mitigate this vulnerability.