Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-22758

No required right warnings about wiki syntax in the context macro's source parameter

    XMLWordPrintable

Details

    • Unit
    • Unknown
    • N/A
    • N/A

    Description

      Steps to reproduce:

      As a user without script right, create a page with content:

      {{context source="string:{{velocity~}~}Evil{{/velocity~}~}"}}{{/context}}

      As an admin user, edit the page.

      Expected result:

      There is a warning about the "Evil" script.

      Actual result:

      There is no warning and after saving or after inserting a macro in the WYSIWYG editor, the "Evil" script is executed.

      Attachments

        Issue Links

          Activity

            People

              MichaelHamann Michael Hamann
              MichaelHamann Michael Hamann
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: