What is CVE-2024-58355?
CVE-2024-58355 is a stored XSS vulnerability in Cal.com (calcom/cal.diy) through version 4.7.15, caused by rendering booking-question field labels via `dangerouslySetInnerHTML` without proper sanitization. This allows an attacker to inject malicious scripts, potentially affecting single booking views at `/booking/<id>`, and users should upgrade to the latest version immediately to mitigate the risk.
Azərbaycanca: CVE-2024-58355: Cal.com (calcom/cal.diy) platformasının 4.7.15 daxil olmaqla bütün versiyalarında saxlanılan XSS zəifliyi aşkar edilib. Bu boşluq fərdi bron görünüşündə istifadəçi tərəfindən daxil edilmiş sual etiketlərinin təhlükəsizlik yoxlaması olmadan `dangerouslySetInnerHTML` vasitəsilə render edilməsi səbəbindən yaranır və təcavüzkara JavaScript kodu yeritməyə imkan verir. Təsirə məruz qalan sistemlərdə brauzerdə ixtiyari kod icrasının qarşısını almaq üçün dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of Cal.com are affected by CVE-2024-58355?
The vulnerability affects all versions of Cal.com (calcom/cal.diy) up to and including version 4.7.15.
What is the root cause of the stored XSS vulnerability in CVE-2024-58355?
The vulnerability is caused by rendering booking-question field labels via `dangerouslySetInnerHTML` without proper sanitization.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.