An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur.
References
Link Resource
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/Wikibase/+/933663 Release Notes Vendor Advisory
https://phabricator.wikimedia.org/T250720 Exploit Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-06-30T00:00:00

Updated: 2023-06-30T00:00:00

Reserved: 2023-06-30T00:00:00


Link: CVE-2023-37301

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-06-30T17:15:09.527

Modified: 2023-07-07T18:26:42.243


Link: CVE-2023-37301

JSON object: View

cve-icon Redhat Information

No data.