CVE-2026-104439
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit emails to the MotDePassePerdu recovery page without rate limiting to identify valid accounts for targeted phishing or password-spraying.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| YesWiki | yeswiki | 0 < 4.6.7 | affected |
| YesWiki | yeswiki | 4.6.7 | unaffected |
Weaknesses
- CWE-204: Observable Response Discrepancy
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: partial
Additional References
References
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-892r-45m6-45xc
- https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-user-enumeration-via-lost-password-flow
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.