Description
An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. During item merging, ItemMergeInteractor does not have an edit filter running (e.g., AbuseFilter).
Remediation
References
Related Vulnerabilities
Moodle Improper Authentication Vulnerability (CVE-2014-0214)
Moodle Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-25978)
IBM RTC Session Fixation Vulnerability (CVE-2018-1492)
WordPress Plugin Helpful Security Bypass (4.5.14)
Liferay Portal Incorrect Authorization Vulnerability (CVE-2021-33335)