Horizon Alert
Summary of the vulnerability and why it matters
Cal.com's booking pages may allow authenticated users to inject malicious code, potentially leading to unauthorized actions or data exposure for visitors of those pages. The main concern is confirming relevance and exposure.
- Malicious code can run on visitor browsers.
- It impacts public-facing booking pages.
- Confirm if our booking pages are affected.
Attack Path
How an attacker could exploit the issue
An attacker with authenticated access to an event can inject malicious JavaScript into a booking page by providing a crafted analytics tracking ID. This script then executes in the browsers of visitors to the public booking page, potentially allowing the attacker to steal session cookies, forge requests, or spread the attack to other events.
- Authenticated event owner access required.
- Inject JavaScript via analytics tracking ID.
- Steal cookies, forge requests, propagate.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could impact users who visit public booking pages on affected Cal.com Cal.diy instances. Authenticated event owners could inject malicious JavaScript into the booking page via a crafted analytics tracking ID. This script could then execute in the browsers of visitors, potentially leading to session cookie theft or the creation of fraudulent requests.
- Public booking pages are at risk.
- Malicious script injection via tracking ID.
- Session hijacking and forged requests.
Operational Fix
Recommended remediation, mitigation, and detection steps
Real-world ownership likely falls to the application team managing Cal.com/Cal.diy and potentially the platform team if Cal.diy is a managed service. The first practical step is to identify all Cal.diy instances, confirm their public reachability and business criticality, and then engage the accountable owner to plan remediation.
- Application and platform teams own the fix.
- Verify public booking page reachability.
- Plan remediation based on exposure risk.