CyberRota Analysis
AI-GeneratedThe vulnerability allows any authenticated user to exploit the lack of authorization in webhook teamId creation, enabling them to inject unvalidated teamIds and create webhooks for any team. This could lead to unauthorized access to sensitive booking data, including organizer and attendee emails, custom responses, and potentially video-call passwords. Organizations using Cal.com OSS should prioritize addressing this critical issue to protect user data and maintain the integrity of their systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally video-call passwords, by triggering webhook delivery.