Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts, making exploitation unlikely. However, combined with a CSP bypass (which is not currently known) the vulnerability could be used to impersonate other organizers or staff users.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://pretix.eu/about/en/blog/20240823-release-2024-7-1/ |
History
Thu, 12 Sep 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Pretix
Pretix pretix |
|
CPEs | cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:* | |
Vendors & Products |
Pretix
Pretix pretix |
|
Metrics |
cvssV3_1
|
Fri, 30 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 23 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts, making exploitation unlikely. However, combined with a CSP bypass (which is not currently known) the vulnerability could be used to impersonate other organizers or staff users. | |
Title | Stored XSS in Placeholder Samples in Mail Preview | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: rami.io
Published: 2024-08-23T14:18:05.416Z
Updated: 2024-08-30T18:40:02.041Z
Reserved: 2024-08-23T08:52:05.098Z
Link: CVE-2024-8113
Vulnrichment
Updated: 2024-08-30T18:39:56.365Z
NVD
Status : Analyzed
Published: 2024-08-23T15:15:17.593
Modified: 2024-09-12T18:21:30.677
Link: CVE-2024-8113
Redhat
No data.