CVE-2025-24019
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 21, 2025
CWE ID 22
Summary
CVE-2025-24019 is a vulnerability affecting YesWiki, a PHP-based wiki system. In versions up to 4.4.5, authenticated users can exploit the filemanager to delete any file owned by the FastCGI Process Manager (FPM), leading to partial data loss and website defacement. In standard installations, the PHP files may also be owned by the same user as the FPM process, enabling attackers to delete crucial files like index.php or YesWiki core files, rendering the wiki inaccessible. The vulnerability is patched in version 4.5.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Yeswiki