Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-20190

User can become admin of a space by creating an AWM app

    XMLWordPrintable

Details

    • Integration
    • Unknown
    • N/A

    Description

      Reproduction step:

      Expected results:
      The users does not have more rights than necessary.

      Actual result:
      The user is Admin (implying Script right) of the "Test" space (including its sub-pages), allowing a untrusted user to create pages with persistence XSS (among other things).

      Note 1: the affect versions needs to be refined.
      Note 2: Probably a side effect by any other non-admin user clicking on "More application" at the top left is redirected to a page with the following message "You are not allowed to view this page or perform this action." (http://localhost:8080/xwiki/bin/admin/XWiki/XWikiPreferences?editor=globaladmin&section=XWiki.AddExtensions)

      Attachments

        Issue Links

          Activity

            People

              MichaelHamann Michael Hamann
              mleduc Manuel Leduc
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: