CVE-2018-1000641

CRITICAL

YesWiki <= cercopitheque beta 1 - Code Injection

Title source: llm

Description

YesWiki version <= cercopitheque beta 1 contains a PHP Object Injection vulnerability in Unserialising user entered parameter in i18n.inc.php that can result in execution of code, disclosure of information.

Scores

CVSS v3 9.8
EPSS 0.0078
EPSS Percentile 73.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (3)

yeswiki/yeswiki
yeswiki/yeswiki
yeswiki/yeswiki

Timeline

Published Aug 20, 2018
Tracked Since Feb 18, 2026