YesWiki
cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*
- <= 4.4.5
A vulnerability allowing authenticated users to delete any file owned by the user running the FastCGI Process Manager (FPM) has been identified in YesWiki versions through 4.4.5. This issue arises from the filemanager's lack of restrictions on the filesystem's scope, enabling the deletion of files attached to wiki pages or files in the /tmp directory. In standard installations, this could also include critical PHP files, potentially disrupting access to the wiki.
Exploitation of this vulnerability leads to unauthorized deletion of files, causing data loss and defacement of the affected wiki. In some cases, it could allow for the removal of essential PHP files, disrupting the functionality of the wiki entirely.
The vulnerability can be reproduced by uploading a file to a wiki page as an authenticated user, then using the filemanager to delete the file. This can be done by accessing the page's filemanager, selecting the uploaded file, and choosing the delete option. The same process can be applied to files in the /tmp directory by creating a file as the user running the application and then deleting it through the filemanager.
Users are advised to update to YesWiki version 4.5.0, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.