CVE-2023-45372: Medium severity mediawiki vulnerability
An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. During item merging, ItemMergeInteractor does not have an edit filter running (e.g., AbuseFilter).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45372?
CVE-2023-45372 is an issue discovered in the Wikibase extension for MediaWiki before version 1.35.12, 1.36.x through 1.39.x before version 1.39.5, and 1.40.x before version 1.40.1.
What is the severity of CVE-2023-45372?
The severity of CVE-2023-45372 is medium with a CVSS score of 5.3.
How does CVE-2023-45372 affect MediaWiki?
CVE-2023-45372 affects the Wikibase extension for MediaWiki versions before 1.35.12, 1.36.x through 1.39.x before version 1.39.5, and 1.40.x before version 1.40.1.
What is the impact of CVE-2023-45372?
CVE-2023-45372 allows an attacker to bypass the edit filter during item merging in the Wikibase extension of MediaWiki.
How can I fix CVE-2023-45372?
To fix CVE-2023-45372, update MediaWiki to version 1.35.12, 1.39.5, or 1.40.1 depending on your installed version.