Details
-
Bug
-
Resolution: Fixed
-
Major
-
8.4.4, 8.4.5, 11.10.2
-
Unit
-
High
-
Easy
-
N/A
-
N/A
-
Description
Steps to reproduce:
1. Create new user.
2. Deny scripting right for the new user.
3. Log in with the new user.
4. Click Dashboard from App Panel
5. Edit
6. Add Velocity Gadget and write some code.
7. Save
Code is executed.
The same works for User Profile dashboard.
The same for Python macro.
Attachments
Issue Links
- is duplicated by
-
XWIKI-16960 Authenticated server side code execution without programming rights
- Closed
- relates to
-
XWIKI-17794 RCE via Gadget title
- Closed
- links to