YesWiki contact mail handler allows unauthenticated SMTP relay
YesWiki before 4.6.7 does not authenticate requests to the contact mail AJAX handler, allowing unauthenticated attackers to send email through the wiki's configured SMTP server.
- Vendor
- YesWiki / Outils-Réseaux
- Product
- YesWiki (before 4.6.7)
- CVSS
- 6.5
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
YesWiki before 4.6.7 accepts POST requests to the contact mail AJAX handler without requiring authentication. Any unauthenticated attacker can submit a request and relay arbitrary email through the wiki’s configured SMTP server. This exposes the mail server to abuse for spam distribution and phishing campaigns.
Affected versions: YesWiki before 4.6.7
Fixed in: YesWiki 4.6.7 (released 2026-10-02)
Mitigation: Update to 4.6.7. If immediate update is not possible, revoking outbound mail access at the server or firewall level limits relay abuse while an update is staged.
References:
