Users without admin rights have access to AdminTools.SpammedPages.
View rights are not restricted only to admin users for AdminTools.SpammedPages. While no data is visible to non admin users, the page is still accessible.
Set the view rights for the AdminTools space to be only available for the XWikiAdminGroup.
{
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [
"CWE-276"
],
"nvd_published_at": null,
"github_reviewed_at": "2025-11-18T17:42:53Z"
}