CVE-2023-37301: Weak Encryption
Published Jun 30, 2023
·Updated
An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur.
Affected Software
1 affected component
MediaWiki MediaWiki<=1.39.3
Event History
Jun 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-37301.
2
What is the affected software?
The affected software is MediaWiki versions up to and including 1.39.3.
3
What is the severity of CVE-2023-37301?
The severity of CVE-2023-37301 is medium with a CVSS score of 5.3.
4
What is the description of CVE-2023-37301?
CVE-2023-37301 is an issue discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3 where the intended interaction with AbuseFilter does not occur.
5
Is there a fix available for CVE-2023-37301?
Yes, the fix for CVE-2023-37301 can be found in the official MediaWiki extension repository.