Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-20234

It's possible to execute anything with superadmin right through comments and async macro

    XMLWordPrintable

Details

    • Unit
    • Unknown
    • N/A
    • N/A

    Description

      That means that if you use the async macro in a restricted context, its content is itself not going to be restricted.

      To reproduce, add a comment with the following content:

      {{async}}
      {{velocity}}velocity{{/velocity}}
      {{/async}}
      

      Expected result:

      An error just like when you use the velocity macro alone.

      Actual result:

      The velocity is executed.

      Attachments

        Issue Links

          Activity

            People

              tmortagne Thomas Mortagne
              tmortagne Thomas Mortagne
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: