Impact
A stored cross‑site scripting flaw exists in Cal.com Cal.diy’s BookingPageTagManager component. An authenticated event owner can supply a malicious analytics tracking ID that is not sanitized, allowing the attacker to inject arbitrary JavaScript. The script runs in the browsers of all visitors to the affected public booking page, enabling session cookie theft, forged authenticated requests, and wormable propagation by chaining with CSRF‑able endpoints to persist payloads on additional events.
Affected Systems
Cal.com Cal.diy self‑hosted installations from version 2.1.1 up through 6.2.0 are impacted. Users running any of these releases must verify their installed version and apply the appropriate fix or upgrade to a later release.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. EPSS data is not available, so exploitation likelihood cannot be quantified precisely; however the high score combined with the requirement for authenticated event‑owner access means the risk remains substantial. The attack vector is limited to users with event‑management rights, yet the impact extends to all visitors of the public booking page, and the ability to chain the injected payload with existing CSRF‑able endpoints makes the vulnerability wormable.
OpenCVE Enrichment