YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| yeswiki/yeswiki(Packagist) | 0 | 4.5.2 | N/A |
CVSS Metrics