{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cal.com--4.7.16/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.9,"id":"CVE-2024-58355"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cal.com (\u003c 4.7.16)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","client-side-execution"],"_cs_type":"advisory","_cs_vendors":["Cal.com"],"content_html":"\u003cp\u003eCal.com (calcom/cal.diy) versions through 4.7.15 are affected by a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2024-58355. This flaw stems from improper sanitization of user-supplied input when rendering booking-question field labels via React's \u003ccode\u003edangerouslySetInnerHTML\u003c/code\u003e function within the single booking view (e.g., \u003ccode\u003ehttps://app.cal.com/booking/\u0026lt;id\u0026gt;\u003c/code\u003e). An attacker with the ability to create an event type can craft a malicious booking-question label containing arbitrary HTML or JavaScript. When a victim subsequently accesses the specially crafted booking URL, the embedded script executes in their browser context. This client-side code execution can lead to various malicious activities, including session hijacking, data exfiltration, or defacement of the victim's browser session. The vulnerability was discovered and subsequently patched in Cal.com version 4.7.16, making an update critical for all affected instances.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker creates a new event type within the vulnerable Cal.com application.\u003c/li\u003e\n\u003cli\u003eDuring the event type creation, the attacker embeds malicious HTML or JavaScript code into the booking-question label field.\u003c/li\u003e\n\u003cli\u003eThe Cal.com application stores this unsanitized malicious payload in its database.\u003c/li\u003e\n\u003cli\u003eThe attacker shares the URL to the crafted single booking view (e.g., \u003ccode\u003ehttps://app.cal.com/booking/\u0026lt;id\u0026gt;\u003c/code\u003e) with a target victim.\u003c/li\u003e\n\u003cli\u003eThe victim navigates to the provided booking URL in their web browser.\u003c/li\u003e\n\u003cli\u003eThe Cal.com application retrieves the stored, malicious booking-question label and renders it on the page using React's \u003ccode\u003edangerouslySetInnerHTML\u003c/code\u003e without proper sanitization.\u003c/li\u003e\n\u003cli\u003eThe embedded arbitrary HTML or JavaScript code executes within the victim's browser context.\u003c/li\u003e\n\u003cli\u003eThe attacker's script performs actions such as stealing session cookies, redirecting the user, or defacing the webpage, achieving impact.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-58355 allows for client-side code execution in the context of the victim's browser session. This can lead to a range of severe consequences for individual users and potentially the organization using Cal.com. Attackers can hijack user sessions, gaining unauthorized access to their Cal.com accounts or other services if single sign-on is used. Sensitive data, including personal information or meeting details, could be exfiltrated to attacker-controlled infrastructure. Additionally, the attacker could deface the web interface, perform phishing attacks, or redirect users to malicious websites, undermining user trust and the integrity of the Cal.com platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2024-58355 immediately by upgrading all Cal.com instances to version 4.7.16 or newer.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) to detect and block common XSS payloads in HTTP request parameters, specifically those targeting input fields that could be rendered unsanitized, even though this is a stored XSS, WAFs can add a layer of protection during initial payload submission.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests related to event creation or booking configurations (\u003ccode\u003e/booking/\u0026lt;id\u0026gt;\u003c/code\u003e) that contain unusual characters or script patterns in query strings or post bodies, indicating potential XSS payload attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T22:23:06Z","date_published":"2026-07-23T22:23:06Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2024-58355-calcom-xss/","summary":"A stored cross-site scripting (XSS) vulnerability, CVE-2024-58355, affects Cal.com (calcom/cal.diy) versions through 4.7.15, allowing an attacker to inject arbitrary HTML/JavaScript into a booking-question label that executes in a victim's browser when they view a crafted booking URL, potentially leading to session hijacking, data theft, or defacement.","title":"Cal.com Stored Cross-Site Scripting Vulnerability (CVE-2024-58355)","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2024-58355-calcom-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cal.com (\u003c 4.7.16)","version":"https://jsonfeed.org/version/1.1"}