CVE Vulnerabilities

CVE-2023-45372

Published: Oct 09, 2023 | Modified: Oct 12, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. During item merging, ItemMergeInteractor does not have an edit filter running (e.g., AbuseFilter).

Affected Software

Name Vendor Start Version End Version
Mediawiki Mediawiki * 1.35.12 (excluding)
Mediawiki Mediawiki 1.36.0 (including) 1.39.5 (excluding)
Mediawiki Mediawiki 1.40.0 (including) 1.40.0 (including)

References