XWiki AdminTools application doesn't set permissions on the AdminTools space
Moderate severity
GitHub Reviewed
Published
Nov 18, 2025
in
xwikisas/application-admintools
•
Updated Nov 18, 2025
Package
Affected versions
< 1.1
Patched versions
1.1
Description
Published to the GitHub Advisory Database
Nov 18, 2025
Reviewed
Nov 18, 2025
Last updated
Nov 18, 2025
Impact
Users without admin rights have access to
AdminTools.SpammedPages.Details
View rights are not restricted only to admin users for
AdminTools.SpammedPages. While no data is visible to non admin users, the page is still accessible.Workarounds
Set the view rights for the
AdminToolsspace to be only available for theXWikiAdminGroup.References