CVE-2025-46347
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 29, 2025
Updated: May 9, 2025
CWE ID 116
Summary
CVE-2025-46347 is a remote code execution vulnerability affecting the YesWiki wiki system before version 4.5.4. An attacker can exploit this flaw by performing an arbitrary file write, creating a file with a PHP extension that can be executed when accessed through a web browser. This vulnerability can lead to a complete compromise of the server, potentially without the user's knowledge. The issue has been addressed in the latest version, 4.5.4.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Yeswiki