← Zurück zur CVE-Suche

CVE-2026-13225

pretix

Beschreibung

Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that order.

CVSS 5.3EPSS 0.345%Risiko 0.55
Quelle öffnen
Veröffentlicht
2026-06-25 15:16:34
Betroffene Versionen
unknown
Typ
Webanwendung
Vektor
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X