← Back

CVE-2025-31131

Published: Apr 1, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.

Affected (1)

Products: Yeswiki: Yeswiki
1 product
Yeswiki
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.5.2

References (2)

Timeline

No history available yet.