PageSourceSearch

https://hackviser.com/assets/js/dc08e5c6.dae6c607.js

js hackviser.com collected 2026-10-03 20:27:33 UTC 6,181 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkhackviser_website=self.webpackChunkhackviser_website||[]).push([[560],{32500:(e,i,t)=>{t.r(i),t.d(i,{assets:()=>l,contentTitle:()=>r,default:()=>u,frontMatter:()=>n,metadata:()=>c,toc:()=>o});var a=t(17624),s=t(4552);const n={title:"YesWiki < 4.5.2 Unauthenticated Path Traversal (CVE-2025-31131) ",description:"Practice YesWiki < 4.5.2 Unauthenticated Path Traversal (CVE-2025-31131) in a hands-on Hackviser lab. Learn CVE-2025-31131 impact, scope, and affected versions.",hide_title:!0,layout:"lab-detail",category_slug:"common-vulnerabilities",category:"Common Vulnerabilities",topic:"CVE 2025",access:"VIP",points:10,premium:!0,app_slug:"cve-2025-31131",cve:["CVE-2025-31131"],cve_details:[{id:"CVE-2025-31131",severity:"High",cvss_score:"8.6",cvss_version:"3.1",cvss_vector:"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",cwe:["CWE-22"],affected_product:"YesWiki before 4.5.2",published:"2025-04-01"}]},r=void 0,c={id:"common-vulnerabilities/cve-2025-31131",title:"YesWiki < 4.5.2 Unauthenticated Path Traversal (CVE-2025-31131) ",description:"Practice YesWiki < 4.5.2 Unauthenticated Path Traversal (CVE-2025-31131) in a hands-on Hackviser lab. Learn CVE-2025-31131 impact, scope, and affected versions.",source:"@site/labs/common-vulnerabilities/cve-2025-31131.md",sourceDirName:"common-vulnerabilities",slug:"/common-vulnerabilities/cve-2025-31131",permalink:"/labs/common-vulnerabilities/cve-2025-31131",draft:!1,unlisted:!1,tags:[],version:"current",frontMatter:{title:"YesWiki < 4.5.2 Unauthenticated Path Traversal (CVE-2025-31131) ",description:"Practice YesWiki < 4.5.2 Unauthenticated Path Traversal (CVE-2025-31131) in a hands-on Hackviser lab. Learn CVE-2025-31131 impact, scope, and affected versions.",hide_title:!0,layout:"lab-detail",category_slug:"common-vulnerabilities",category:"Common Vulnerabilities",topic:"CVE 2025",access:"VIP",points:10,premium:!0,app_slug:"cve-2025-31131",cve:["CVE-2025-31131"],cve_details:[{id:"CVE-2025-31131",severity:"High",cvss_score:"8.6",cvss_version:"3.1",cvss_vector:"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",cwe:["CWE-22"],affected_product:"YesWiki before 4.5.2",published:"2025-04-01"}]}},l={},o=[{value:"Vulnerability Overview",id:"vulnerability-overview",level:3},{value:"Impact",id:"impact",level:3},{value:"Vulnerability Scope",id:"vulnerability-scope",level:3},{value:"Lab Focus",id:"lab-focus",level:3},{value:"Resources",id:"resources",level:3}];function d(e){const i={a:"a",code:"code",h3:"h3",li:"li",p:"p",ul:"ul",...(0,s.M)(),...e.components};return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(i.p,{children:"YesWiki < 4.5.2 Unauthenticated Path Traversal, tracked as CVE-2025-31131, affects YesWiki installations where a template-related parameter can be used to read files outside the intended directory. YesWiki is a PHP-based wiki system for collaborative content, so file disclosure can expose application configuration and server-side data."}),"\n",(0,a.jsx)(i.h3,{id:"vulnerability-overview",children:"Vulnerability Overview"}),"\n",(0,a.jsxs)(i.p,{children:["CVE-2025-31131 is a path traversal vulnerability in YesWiki's ",(0,a.jsx)(i.code,{children:"squelette"})," parameter. The vulnerable parameter can allow read access to arbitrary files on the server when input is not properly constrained to the expected template directory."]}),"\n",(0,a.jsx)(i.p,{children:"The issue is unauthenticated, which means an attacker does not need a valid YesWiki account to reach the vulnerable behavior on an exposed affected instance."}),"\n",(0,a.jsx)(i.h3,{id:"impact",children:"Impact"}),"\n",(0,a.jsx)(i.p,{children:"The vulnerability is rated High with a CVSS 3.1 score of 8.6 by the GitHub advisory. Successful exploitation can expose sensitive local files, including application configuration, source code, logs, or credentials readable by the web application process."}),"\n",(0,a.jsx)(i.p,{children:"The primary impact is confidentiality loss rather than code execution. For a wiki platform, exposed configuration files can still lead to broader compromise if they contain database credentials or integration secrets."}),"\n",(0,a.jsx)(i.h3,{id:"vulnerability-scope",children:"Vulnerability Scope"}),"\n",(0,a.jsx)(i.p,{children:"The affected product is YesWiki before 4.5.2. The vulnerability is fixed in YesWiki 4.5.2."}),"\n",(0,a.jsx)(i.p,{children:"The highest-risk deployments are public YesWiki installations running versions earlier than 4.5.2 where the vulnerable parameter can be reached by unauthenticated users."}),"\n",(0,a.jsx)(i.h3,{id:"lab-focus",children:"Lab Focus"}),"\n",(0,a.jsx)(i.p,{children:"This Hackviser lab focuses on understanding how path traversal in template selection or file loading logic can expose server-side files. You will practice identifying affected YesWiki versions, recognizing arbitrary file read impact, and connecting path traversal risk to PHP application hardening."}),"\n",(0,a.jsx)(i.h3,{id:"resources",children:"Resources"}),"\n",(0,a.jsxs)(i.ul,{children:["\n",(0,a.jsx)(i.li,{children:(0,a.jsx)(i.a,{href:"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-w34w-fvp3-68xm",children:"GitHub Advisory - GHSA-w34w-fvp3-68xm"})}),"\n",(0,a.jsx)(i.li,{children:(0,a.jsx)(i.a,{href:"https://github.com/YesWiki/yeswiki/commit/f78c915369a60c74ab8f38561ae93a4aaca9b989",children:"YesWiki Patch Commit"})}),"\n",(0,a.jsx)(i.li,{children:(0,a.jsx)(i.a,{href:"https://nvd.nist.gov/vuln/detail/CVE-2025-31131",children:"NVD - CVE-2025-31131"})}),"\n",(0,a.jsx)(i.li,{children:(0,a.jsx)(i.a,{href:"https://www.cve.org/CVERecord?id=CVE-2025-31131",children:"CVE.org - CVE-2025-31131"})}),"\n"]})]})}function u(e={}){const{wrapper:i}={...(0,s.M)(),...e.components};return i?(0,a.jsx)(i,{...e,children:(0,a.jsx)(d,{...e})}):d(e)}},4552:(e,i,t)=>{t.d(i,{I:()=>c,M:()=>r});var a=t(11504);const s={},n=a.createContext(s);function r(e){const i=a.useContext(n);return a.useMemo((function(){return"function"==typeof e?e(i):{...i,...e}}),[i,e])}function c(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:r(e.components),a.createElement(n.Provider,{value:i},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.