CVE-2023-37301 Information

Share on:

Description

An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn’t use EditEntity for undo and restore the intended interaction with AbuseFilter does not occur.

Reference

https://phabricator.wikimedia.org/T250720 https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Wikibase/+/933663