Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-21949

Restrict the execution of script macros during a realtime WYSIWYG editing session

    XMLWordPrintable

Details

    • Integration
    • Unknown
    • N/A

    Description

      Starting with XWIKI-21767 a change in a macro parameter / content triggers a re-rendering of the macro output for each participant. This creates a security vulnerability: a user without script rights will be able to execute scripts if any other participant has script right because whatever script macro they insert will be executed automatically by the rest of the users.

      In order to fix this we could:

      • prevent users with different script/programming level enter the same realtime WYSIWYG editing session
      • or prevent the execution of script macros during a realtime WYSIWYG editing session (but this will remove the WYSIWYG aspect).

      Attachments

        Issue Links

          Activity

            People

              mflorea Marius Dumitru Florea
              mflorea Marius Dumitru Florea
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: