An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur.
References
Link | Resource |
---|---|
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Wikibase/+/933663 | Release Notes Vendor Advisory |
https://phabricator.wikimedia.org/T250720 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-06-30 17:15
Updated : 2023-07-07 18:26
NVD link : CVE-2023-37301
Mitre link : CVE-2023-37301
CVE.ORG link : CVE-2023-37301
JSON object : View
Products Affected
mediawiki
- mediawiki
CWE