Steps to reproduce:
to any place where you can use wiki syntax like the "about" section in your user profile as a user without programming or script rights.
An empty VFS Tree or some error is displayed.
is displayed. This shows that the Groovy macro has been executed and thus programming rights have been gained. This is because the VFS Tree macro allows XWiki syntax injection through the root parameter.
Note that the VFS Tree macro, while being part of xwiki-platform, is not bundled with XWiki and thus this issue cannot be exploited on a default installation of XWiki.