Details
-
Bug
-
Resolution: Duplicate
-
Critical
-
None
-
4.5.1
-
Unknown
-
Description
A user with edit rights can create a custom skin, override a template and execute PR code, as long as he uses the skin on a page that already has PR.
The attached skin is saved by a user without PR, but if the user applies the skin on a page saved with PR (like Main.WebHome), the overridden template in the skin executes with PR:
http://localhost:8080/xwiki/bin/view/Main/WebHome?skin=Main.NOPRSkin
outputs:
com.xpn.xwiki.XWiki@7c6277d8
Attachments
Issue Links
- duplicates
-
XWIKI-11202 Wiki based skin templates are executed with the right of current document
- Closed