Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-46549 PoC — YesWiki 跨站脚本漏洞

Source
Associated Vulnerability
Title:YesWiki 跨站脚本漏洞 (CVE-2025-46549)
Description:YesWiki是法国YesWiki组织的一个用 PHP 编写的 wiki 系统。用于以协作方式创建和管理网站。 YesWiki 4.5.4之前版本存在跨站脚本漏洞,该漏洞源于反射型跨站脚本攻击,可能导致会话劫持。
Description
YesWiki <= 4.5.1 contains a reflected cross-site scripting caused by insufficient sanitization in user input, letting attackers steal cookies and hijack sessions, exploit requires user to click malicious link.
File Snapshot

id: CVE-2025-46549 info: name: YesWiki <= 4.5.1 - Cross-Site Scripting author: MuhammadWaseem ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.