Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
3.0 M1
Description
To my mind such a feature should be restricted to users with PR since such scripts can be dangerous.
Attachments
Issue Links
- depends on
-
XWIKI-9282 Add a way to restrict access to some classes
- Open
- is duplicated by
-
XWIKI-19514 XSS using a JSX object
- Closed
-
XWIKI-19583 Privilege escalation via style sheet skin extensions with just edit rights
- Closed