Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
14.0-rc-1
-
Unknown
-
N/A
-
N/A
-
Description
Steps to reproduce:
- As a user without script or programming right open your user account (or any other document you can edit with the wiki editor.
- Set the content to
{{display reference="{{cache~}~}{{groovy~}~}println(~"Hello from Groovy~" + ~" in included document!~"){{/groovy~}~}{{/cache~}~}"/}}
.
- Click "Save"
- Refresh the document in the browser.
Expected result:
The panel at the right of the editor displays
One included page: {{cache}}{{groovy}}println("Hello from Groovy" + " in included document!"){{/groovy}}{{/cache}}
.
Actual result:
The panel displays the text
One included page: XWiki.Hello from Groovy in included document!
This demonstrates a privilege escalation from simple user account to programming rights.
Attachments
Issue Links
- links to