Impact
Anyone who has view rights on the Calendar.JSONService page, including guest users can exploit this vulnerability by accessing database info or starting a DoS attack.
Workarounds
Remove the Calendar.JSONService page. This will however break some functionalities.
References
Jira issue: FULLCAL-80: SQL injection through Calendar.JSONService FULLCAL-81: SQL injection through Calendar.JSONService still exists
For more information
If there are any questions or comments about this advisory: Open an issue in Jira XWiki.org Email Security Mailing List