pretix Stored Cross-site Scripting vulnerability
High severity
GitHub Reviewed
Published
Aug 23, 2024
to the GitHub Advisory Database
•
Updated Oct 4, 2024
Description
Published by the National Vulnerability Database
Aug 23, 2024
Published to the GitHub Advisory Database
Aug 23, 2024
Reviewed
Aug 23, 2024
Last updated
Oct 4, 2024
Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts, making exploitation unlikely. However, combined with a CSP bypass (which is not currently known) the vulnerability could be used to impersonate other organizers or staff users.
References