Details
-
Bug
-
Resolution: Fixed
-
Minor
-
1.34
-
None
Description
Registration checked for register permission on itself while api.XWiki#createUser checked on XWikiPreferences. If Registration had PR and had register permission set true then users would be allowed in even if global register was denied. I don't think it's exploitable since Registration would need PR.