GHSA-2g22-wg49-fgv5
Impact
Anyone who has view rights on the Calendar.JSONService page, including guest users can exploit this vulnerability by accessing database info or starting a DoS attack.
Workarounds
Remove the Calendar.JSONService page. This will however break some functionalities.
References
Jira issue:
- FULLCAL-80: SQL injection through Calendar.JSONService
- FULLCAL-81: SQL injection through Calendar.JSONService still exists
For more information
If there are any questions or comments about this advisory:
- Open an issue in Jira XWiki.org
- Email Security Mailing List
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/xwiki-contrib/macro-fullcalendar/security/advisories/GHSA-2g22-wg49-fgv5, https://nvd.nist.gov/vuln/detail/CVE-2025-65091, https://github.com/xwiki-contrib/macro-fullcalendar/commit/5fdcf06a05015786492fda69b4d9dea5460cc994, https://github.com/xwiki-contrib/macro-fullcalendar
