Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-1772

Any user can execute groovy via xml/rpc

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Major
    • 2.0.3, 2.1 M1
    • 1.1
    • {Unused} Core
    • None
    • Integration
    • High

    Description

      Any user can execute groovy code on the wiki through the XML/RPC interface function confluence1.renderContent.

      The page name given to renderContent needs to be the page name
      of an exisiting page, saved by an user with programmingrights.

      Exemple perl code attached

      Attachments

        Activity

          People

            tmortagne Thomas Mortagne
            raffaello Raffaello Pelagalli
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: