Details
-
Bug
-
Resolution: Fixed
-
Critical
-
3.1 M2
-
Unknown
-
N/A
-
N/A
-
Description
PR rigths of a translated document are checks against the author of the original document.
This could be easily exploited to execute code with PR rights, event in a monolingual wiki, using the language= query string.
Attachments
Issue Links
- relates to
-
XWIKI-7879 Refactor to confine delegation of programming rights.
- In Progress