CyberRota Analysis
AI-GeneratedYesWiki versions prior to 4.6.6 are vulnerable to an authenticated PHP object injection flaw in the BazarImportAction component, which can be exploited to execute arbitrary code. This critical vulnerability, with a CVSS score of 9.4, poses a significant risk to any organization using affected versions of YesWiki. Administrators should prioritize updating to version 4.6.6 or later to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.