Stored Cross-Site Scripting Vulnerability in Cal.com by Cal.com
CVE-2024-58355
9.3CRITICAL
What is CVE-2024-58355?
Cal.com versions up to 4.7.15 are vulnerable to a stored cross-site scripting (XSS) flaw. This issue arises from the 'booking-question' field labels being rendered unsanitized via React's dangerouslySetInnerHTML, allowing an attacker to inject malicious JavaScript or HTML into the application. When a victim accesses a specially crafted booking URL, the injected code can execute in their browser, potentially compromising user data or leading to other malicious actions. The vulnerability has been addressed in version 4.7.16.
Affected Version(s)
cal.diy 0 <= 4.7.15
