A vulnerability was found in calcom cal.diy up to 4.7.15. It has been rated as problematic. Affected by this issue is the function dangerouslySetInnerHTML of the component Booking Question Label. The manipulation of the argument booking-question leads to cross site scripting.

This vulnerability is listed as CVE-2024-58355. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.