Impact
Cal.com, in the calcom/cal.diy repository, has a cross‑site scripting flaw in all releases up to and including version 4.7.15. The vulnerable area is the booking‑question label, which is rendered with React’s dangerouslySetInnerHTML without sanitization. An attacker who can create an event type can insert arbitrary HTML or JavaScript into the label, and the code will execute in the browser of any user who visits the public booking URL. This flaw allows the attacker to run code with the victim’s browser context.
Affected Systems
Affected systems are self‑hosted Cal.com installations that use the calcom/cal.diy product and are running any version up to 4.7.15. Systems that allow open registration or permit unauthenticated users to create event types are at higher risk.
Risk and Exploitability
The CVSS score of 9.3 denotes a high‑severity vulnerability. The EPSS score of less than 1% indicates a low probability of exploitation in the wild at the time of this analysis. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker’s ability to create a malicious event type, after which the injected script runs when a visitor opens the public booking page.
OpenCVE Enrichment