Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-20234

It's possible to execute anything with superadmin right through comments and async macro

    XMLWordPrintable

Details

    • Unit
    • Unknown
    • N/A
    • N/A

    Description

      That means that if you use the async macro in a restricted context, its content is itself not going to be restricted.

      To reproduce, add a comment with the following content:

      {{async}}
      {{velocity}}velocity{{/velocity}}
      {{/async}}
      

      Expected result:

      An error just like when you use the velocity macro alone.

      Actual result:

      The velocity is executed.

      Attachments

        Activity

          People

            tmortagne Thomas Mortagne
            tmortagne Thomas Mortagne
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: