GHSA-c9hw-c2mv-jj5cHighCVSS 6.8

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack...

Published
October 2, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers who set or learn a victim's pre-authentication YesWiki-* session cookie can reuse it after login to access private content and perform actions with the victim's privileges.

🔗 References (4)