Impact
Anyone who has view rights on the Calendar.JSONService page, including guest users can exploit this vulnerability by accessing database info or starting a DoS attack.
Workarounds
Remove the Calendar.JSONService page. This will however break some functionalities.
References
Jira issue: FULLCAL-80: SQL injection through Calendar.JSONService FULLCAL-81: SQL injection through Calendar.JSONService still exists
For more information
If there are any questions or comments about this advisory: Open an issue in Jira XWiki.org Email Security Mailing List
Impact Anyone who has view rights on the Calendar.JSONService page, including guest users can exploit this vulnerability by accessing database info, with the exception of passwords.
Workarounds Remove the Calendar.JSONService page. This will however break some functionalities.
References
Jira issue: FULLCAL-82: Calendar.JSONService exposes emails of all users
For more information
If you have any questions or comments about this advisory: Open an issue in Jira XWiki.org Email us at Security Mailing List