Details
-
Type:
Bug
-
Status: Closed
-
Priority:
Minor
-
Resolution: Fixed
-
Affects Version/s: 3.0, 3.1
-
Component/s: XWiki Enterprise Documents
-
Labels:None
-
keywords:csrf
-
Similar issues:
Description
To reproduce:
- enable CSRF protection
- go to user profile
- click on change avatar button
- try to upload, select or delete some avatar