Description
An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is no rate limit for merging items.
Remediation
References
Related Vulnerabilities
Jenkins Incorrect Authorization Vulnerability (CVE-2017-2599)
Envoy Proxy Reachable Assertion Vulnerability (CVE-2021-29258)
WordPress Plugin Neuvoo Jobs Cross-Site Scripting (2.0)
WordPress Plugin Contact Form by Supsystic Multiple Vulnerabilities (1.7.5)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0703)