Uploaded image for project: '{RETIRED} XWiki Administration Application'
  1. {RETIRED} XWiki Administration Application
  2. XAADMINISTRATION-147

XWiki.Registration check of register permission not consistant with api.XWiki#createUser

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Minor
    • 1.35
    • 1.34
    • Users, Groups, Rights
    • None

    Description

      Registration checked for register permission on itself while api.XWiki#createUser checked on XWikiPreferences. If Registration had PR and had register permission set true then users would be allowed in even if global register was denied. I don't think it's exploitable since Registration would need PR.

      Attachments

        Activity

          People

            calebjamesdelisle CalebJamesDeLisle
            calebjamesdelisle CalebJamesDeLisle
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: