We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension.
To reproduce:
tip={{async async="true" cached="false" context="doc.reference"}}{{groovy}}println("Hello " + "from groovy!"){{/groovy}}{{/async}}
The groovy macro is executed, after the fix you get an error instead.
This has been patched in XWiki 15.1-rc-1 and 14.10.5.
There are no known workarounds for it.
If you have any questions or comments about this advisory:
Impact
It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension.
To reproduce:
The groovy macro is executed, after the fix you get an error instead.
Patches
This has been patched in XWiki 15.1-rc-1 and 14.10.5.
Workarounds
There are no known workarounds for it.
References
For more information
If you have any questions or comments about this advisory: