{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cal.com-repository-calcom/cal.diy--4.7.15/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.9,"id":"CVE-2024-58353"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cal.com (repository calcom/cal.diy) \u003c= 4.7.15"],"_cs_severities":["critical"],"_cs_tags":["xss","web-vulnerability","react","dangerouslySetInnerHTML"],"_cs_type":"advisory","_cs_vendors":["Cal.com"],"content_html":"\u003cp\u003eCal.com, specifically the \u003ccode\u003ecalcom/cal.diy\u003c/code\u003e repository, contains a critical cross-site scripting (XSS) vulnerability, identified as CVE-2024-58353, affecting versions up to and including 4.7.15. This vulnerability allows an unauthenticated attacker to inject arbitrary HTML and JavaScript code into \u0026quot;booking question label\u0026quot; fields. The application then renders this unsanitized input via React's \u003ccode\u003edangerouslySetInnerHTML\u003c/code\u003e on publicly accessible single booking views (e.g., \u003ccode\u003e/booking/\u0026lt;id\u0026gt;\u003c/code\u003e). When a victim user visits a malicious booking view URL, the injected script executes in their browser context. This client-side code execution can lead to session hijacking, defacement, or redirection, posing a significant risk, especially for self-hosted Cal.com instances with open registration. The issue is resolved in version 4.7.16.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a vulnerable Cal.com instance (version \u0026lt;= 4.7.15).\u003c/li\u003e\n\u003cli\u003eThe attacker registers or gains access to create new event types within the Cal.com instance.\u003c/li\u003e\n\u003cli\u003eDuring the creation or modification of an event type, the attacker crafts a malicious payload (e.g., \u003ccode\u003e\u0026lt;script\u0026gt;alert(document.domain)\u0026lt;/script\u0026gt;\u003c/code\u003e or a more sophisticated script) and inputs it into a \u0026quot;booking question label\u0026quot; field.\u003c/li\u003e\n\u003cli\u003eThe Cal.com application stores this malicious content in its database without adequately sanitizing the input.\u003c/li\u003e\n\u003cli\u003eThe attacker then obtains the URL for the publicly accessible single booking view associated with the compromised event type (e.g., \u003ccode\u003e/booking/\u0026lt;id\u0026gt;\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe attacker distributes this malicious booking view URL to a victim, typically via social engineering or a direct link.\u003c/li\u003e\n\u003cli\u003eWhen the victim visits the provided booking view URL, the Cal.com application fetches the stored malicious \u0026quot;booking question label.\u0026quot;\u003c/li\u003e\n\u003cli\u003eThe application renders the page using React's \u003ccode\u003edangerouslySetInnerHTML\u003c/code\u003e method, which directly embeds the unsanitized malicious HTML/JavaScript into the victim's browser, leading to client-side code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-58353 allows attackers to execute arbitrary HTML and JavaScript in the context of the victim's browser. The direct consequences can include session hijacking, enabling attackers to impersonate the victim, or website defacement. More advanced attacks could involve redirecting users to malicious sites, stealing sensitive data (e.g., cookies, local storage), or performing actions on behalf of the victim through their authenticated session. Self-hosted Cal.com instances with open registration are particularly vulnerable due to the ease with which attackers can create malicious event types.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Cal.com instances to version 4.7.16 or later immediately to patch CVE-2024-58353.\u003c/li\u003e\n\u003cli\u003eImplement Content Security Policy (CSP) headers across all web applications to mitigate the impact of XSS vulnerabilities by restricting script sources.\u003c/li\u003e\n\u003cli\u003eEnsure proper input validation and output encoding are enforced for all user-supplied data in web applications, especially in fields like the \u0026quot;booking question label\u0026quot; mentioned in the CVE-2024-58353 description.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T22:22:23Z","date_published":"2026-07-23T22:22:23Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2024-58353-calcom-xss/","summary":"CVE-2024-58353 describes a cross-site scripting (XSS) vulnerability in Cal.com (repository calcom/cal.diy) versions up to and including 4.7.15, where an attacker can inject malicious HTML/JavaScript into booking question labels that is then executed via React's dangerouslySetInnerHTML when a victim visits a publicly accessible single booking view, allowing for arbitrary client-side code execution, particularly impacting self-hosted instances with open registration.","title":"CVE-2024-58353: Cal.com Cross-Site Scripting Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2024-58353-calcom-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cal.com (Repository Calcom/Cal.diy) \u003c= 4.7.15","version":"https://jsonfeed.org/version/1.1"}