← Voltar à pesquisa de CVEs

CVE-2026-13225

pretix

Descrição

Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization on the confirmation page for individual tickets in that order.

CVSS 5.3EPSS 0.345%Risco 0.55
Ver fonte
Publicação
2026-06-25 15:16:34
Versões afetadas
unknown
Tipo
Aplicação web
Vetor
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X