CVE-2026-104468
6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Summary
YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who obtain an unused reset URL from mailboxes, logs, backups, or browser history can submit a new password through checkEmailKey() and take over accounts.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| YesWiki | yeswiki | 0 < 4.6.7 | affected |
| YesWiki | yeswiki | 4.6.7 | unaffected |
Weaknesses
- CWE-613: Insufficient Session Expiration
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/YesWiki/yeswiki/security/advisories/GHSA-x3xh-4hx3-rgm7
- https://www.vulncheck.com/advisories/yeswiki-before-4.6.7-non-expiring-password-reset-tokens-via-lostpasswordaction
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.