The class XWiki.EventStream.Code.EventClass should have its own required rights analyzer that indicates the required admin right to allow the correct automatic configuration of required rights. This is not a security vulnerability as the two fields that can contain code are already analyzed as Velocity code and thus trigger warnings. I cannot think of any relevant security impact of a XWiki.EventStream.Code.EventClass where those scripts are empty. |