CVE-2025-46350

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Apr 29, 2025
Updated: May 9, 2025
CWE ID 79

Summary

CVE-2025-46350 is a reflected cross-site scripting (XSS) vulnerability affecting YesWiki, a PHP-based wiki system. Before version 4.5.4, the software was susceptible to XSS attacks, allowing malicious actors to steal cookies from authenticated users. By creating a malicious link, an attacker could trick users into clicking it, resulting in the theft of their session cookies. This vulnerability poses a significant risk, enabling attackers to not only take over user sessions but also deface the website or embed malicious content. Users are strongly advised to upgrade to version 4.5.4 as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share