CVE-2026-104462: YesWiki before 4.6.7 SQL Injection via nuagetag tags parameter
YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. Attackers with page-write access (unauthenticated on default installs) can embed a nuagetag tag ending in a backslash to break quote parity and inject a UNION subquery, exfiltrating password hashes and arbitrary table data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
YesWikito a version that resolves this vulnerability.Fixed in 4.6.7
Event History
Frequently Asked Questions
Are default YesWiki installations exposed to unauthenticated attackers?
Yes. The vulnerable action requires page-write access, and the provided data states that page-write access is unauthenticated on default installations.
What must an attacker do to exploit the issue?
An attacker needs page-write access and must embed a nuagetag tag ending in a backslash. This breaks quote parity in the raw SQL IN clause and enables injection of a UNION subquery.
What data could be exposed through successful exploitation?
Successful exploitation can exfiltrate password hashes and arbitrary data from database tables. The vulnerability description does not indicate integrity or availability impact.