CVE Vulnerabilities

CVE-2023-37301

Published: Jun 30, 2023 | Modified: Nov 27, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesnt use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur.

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.39.3 (including)
Mediawiki Ubuntu bionic *
Mediawiki Ubuntu kinetic *
Mediawiki Ubuntu lunar *
Mediawiki Ubuntu mantic *
Mediawiki Ubuntu trusty *
Mediawiki Ubuntu xenial *

References