Lack of Interaction with AbuseFilter in SubmitEntityAction in Wikibase

Lack of Interaction with AbuseFilter in SubmitEntityAction in Wikibase

CVE-2023-37301 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur.

Learn more about our Web Application Penetration Testing UK.