Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-20361

Regular user can add InvitationConfig Page

    XMLWordPrintable

Details

    • Bug
    • Resolution: Unresolved
    • Major
    • None
    • 14.10.19
    • Invitation
    • None
    • Unknown

    Description

      SUBMISSION REFERENCES

      RESEARCHER INFORMATION

      • Submitter: renniepak

      SUBMISSION INFORMATION

      • Created at: Sat, 12 Nov 2022 15:16:02 GMT
      • Submission status: Archived

      REPORT CONTENT

      I have found a weird issue where a regular user can create a InvitationConfig page although they don't have rights to create any pages. An additional consequence is that this page will show up in the Navigation bar. The user doesn't seem to control any specific characteristics of the Page (like title/path), nor can they delete/edit the created page.

        1. Reproduction

      1. Login as a regular user and navigate to https://intigriti.xwiki.com/xwiki/rest/liveData/sources/liveTable/entries?sourceParams.resultPage=Invitation.InvitationMemberActions

        1. Result

      A new page is added which shows up in the Navigation: https://intigriti.xwiki.com/xwiki/bin/view/%24%7Bdoc/getSpace%28%29%7D/InvitationConfig

      {497590}

      (This is how it will show up on the homepage https://intigriti.xwiki.com/xwiki/bin/view/Main/)

      I also tried this on a local instance. When the admin deletes the created page, the regular user can simply recreate it by going to the same url.

      Attachments

        Activity

          People

            Unassigned Unassigned
            intigriti Intigriti Integration
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: