Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-18849

Private user data are accessible through suggest.vm

    XMLWordPrintable

Details

    • Unit
    • High
    • Unknown
    • N/A

    Description

      Reproduction steps:

      • Go to:
        • http://<server>/bin/login/XWiki/XWikiLogin?xpage=suggest&classname=XWiki.XWikiUsers&templatename=&input=&fieldname=email

      Results:

      • suggets template let access email, password hash and about every user profile information

       

      Expected Results:

      • None of the previous informations should be accessible

      Attachments

        Issue Links

          Activity

            People

              MichaelHamann Michael Hamann
              gcoquard Guillaume COQUARD
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: