Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in the Cal.com scheduling platform, specifically within its booking question feature. This flaw could allow an attacker to inject malicious code that executes when a user accesses a crafted booking link, potentially impacting user experience and data integrity.
- A flaw allows injecting malicious code into booking links.
- High risk to user experience and data integrity if exploited.
- Confirm relevance and verify exposure across affected systems.
Attack Path
How an attacker could exploit the issue
An attacker with a low level of access can create an event type with a malicious label in the booking question field. When a victim views the booking page for this event, the injected HTML or JavaScript code will execute in their browser. This could lead to the theft of sensitive information or further compromise of the victim's session.
- Requires a logged-in user account.
- Triggered by a victim visiting a crafted booking URL.
- Leads to arbitrary code execution.
Live Threat
Current exploitation, exposure, and threat context
A stored cross-site scripting vulnerability in Cal.com could allow an attacker to inject arbitrary HTML and JavaScript into booking question labels. This malicious content could execute when a victim accesses a crafted booking URL, potentially impacting the user's session or redirecting them to a malicious site when supported by the advisory.
- User session data.
- Malicious script injection via booking URL.
- Potential for session hijacking or redirection.
Operational Fix
Recommended remediation, mitigation, and detection steps
The application or platform owner is responsible for this vulnerability, as it affects the Cal.com scheduling platform. The first practical step is to identify all instances of the affected technology, assess their reachability and business criticality, and then confirm the accountable owner for remediation planning.
- Application owners should own the issue.
- Verify public-facing booking views are identified.
- Plan remediation based on identified exposure.