CVE-2024-58355
CRITICAL
9,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
8,9
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: required
Scope: changed
Confidentiality: high
Integrity: high
Availability: low
Description
AI Translation Available
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/<id>) renders booking-question field labels via React's dangerouslySetInnerHTML without sanitizing or escaping user input. An attacker who can create an event type with a malicious booking-question label can inject arbitrary HTML/JavaScript that executes when a victim opens the crafted booking URL. The issue is fixed in v4.7.16.
80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Potential Impacts:
Read Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
Web Based, Web Server
https://github.com/calcom/cal.diy/security/advisories/GHSA-vgj7-76cw-h6f8
https://github.com/calcom/cal.diy/commit/00689fda0a30b8f933c096f02c1fe092a4206d…
https://github.com/calcom/cal.diy/security/advisories/GHSA-vgj7-76cw-h6f8
https://www.vulncheck.com/advisories/cal-com-through-cross-site-scripting-via-b…