Description
An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur.
Remediation
References
Related Vulnerabilities
WordPress Plugin FCChat Widget 'Upload.php' Arbitrary File Upload (2.2.13.1)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-15700)
Plone CMS Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-33509)
WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.3.20)