f0y / redmine_private_wiki

Private Wiki plugin for Redmine
http://www.redmine.org/plugins/private_wiki
MIT License
17 stars 16 forks source link

Security leak: {{include}} macro allows to see private pages #9

Closed wild-paul closed 12 years ago

wild-paul commented 12 years ago

User without permissions to view private wiki page can view page content using {{include}} macro. For example, from ticket description field. Name of hidden page user can get in wiki\index because all pages are shown in index list even hidden.

f0y commented 12 years ago

I'm afraid I can't fix the issue this week. But anyway thanks for the bug report.