Details
-
Bug
-
Resolution: Fixed
-
Major
-
2.0 M1, 1.9.1
-
None
-
Unknown
-
Description
Any subwiki admin can execute any script with programming right by importing a document which as a user with programming right (like "xwiki.XWiki.XWikiAdmin") as content user.
Note that XWIKI-3725 will cover non backup mode. We just need to change de admin test in import package to global admin test when user is asking to import backup pack.
Should not be difficult to do.
Attachments
Issue Links
- relates to
-
XWIKI-8884 Subwiki admin can import as backup a custom xar thus obtaining PR on the imported pages
- Closed