Details
-
Bug
-
Resolution: Fixed
-
Major
-
2.7 RC1, 2.6.1
-
Unknown
-
N/A
-
N/A
-
Description
Reproduction steps:
- Go in Administration > Rights and check "Prevent unregistered users from viewing pages, regardless of the page rights"
- Go to URL such as
http://localhost:8080/xwiki/bin/register/XWiki/XWikiRegister?xredirect=%2fbin%2flogin%2fXWiki%2fXWikiLogin%3fsrid%3dyJi2Etxt%26xredirect%3d%252Fbin%252Fview%252FMain%252F%253Fsrid%253DyJi2Etxtc29tl%22%3e%3cscript%3ealert(1)%3c%2fscript%3ey9vgc
Expected result:
- the registration page is displayed and nothing happens
Obtained result:
- the registration page is displayed but an alert appear
Attachments
Issue Links
- causes
-
XWIKI-21510 No feedback on registration form in close wiki
- Closed
- is caused by
-
XWIKI-5756 Add support for redirect in the register action
- Closed
- links to