Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
1.3 RC1
-
A standard Wiki and a completely closed Wiki
-
Unit
-
High
-
Unknown
-
N/A
-
Description
Reproduction steps:
- Go to:
- http://<server>/bin/login/XWiki/XWikiLogin?xpage=suggest&classname=XWiki.XWikiUsers&templatename=&input=&fieldname=email
Results:
- suggets template let access email, password hash and about every user profile information
Expected Results:
- None of the previous informations should be accessible
Attachments
Issue Links
- is related to
-
XWIKI-18851 Unauthenticated user can retrieve user information through getdeleteddocuments.vm
- Closed
-
XWIKI-16544 Unauthenticated user can retrieve the list of users through getdocuments.vm
- Closed
-
XWIKI-18850 Unauthenticated user can retrieve the list of users through uorgsuggest.vm
- Closed
- links to