Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0150 | Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts, making exploitation unlikely. However, combined with a CSP bypass (which is not currently known) the vulnerability could be used to impersonate other organizers or staff users. |
Github GHSA |
GHSA-45rp-q25w-4426 | pretix Stored Cross-site Scripting vulnerability |
| Link | Providers |
|---|---|
| https://pretix.eu/about/en/blog/20240823-release-2024-7-1/ |
|
Thu, 12 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pretix
Pretix pretix |
|
| CPEs | cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pretix
Pretix pretix |
|
| Metrics |
cvssV3_1
|
Fri, 30 Aug 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts, making exploitation unlikely. However, combined with a CSP bypass (which is not currently known) the vulnerability could be used to impersonate other organizers or staff users. | |
| Title | Stored XSS in Placeholder Samples in Mail Preview | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: rami.io
Published:
Updated: 2024-08-30T18:40:02.041Z
Reserved: 2024-08-23T08:52:05.098Z
Link: CVE-2024-8113
Updated: 2024-08-30T18:39:56.365Z
Status : Analyzed
Published: 2024-08-23T15:15:17.593
Modified: 2024-09-12T18:21:30.677
Link: CVE-2024-8113
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA