PT-2025-48262 · Pretix · Pretix

Jan Roring

·

Published

2025-11-27

·

Updated

2025-12-30

·

CVE-2025-13742

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions pretix (affected versions not specified)
Description The software allows the use of placeholders in email templates that are populated with customer data, such as the attendee's name. If a customer's name contains HTML or Markdown formatting, this formatting is rendered in the final email. While a strict allow list approach prevents cross-site scripting (XSS) or similar attacks, this can be exploited to manipulate emails, potentially enabling phishing attacks by making user-provided content appear trustworthy. The issue involves the rendering of potentially malicious formatting within the name placeholder when constructing emails.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2025-13742
PYSEC-2025-154

Affected Products

Pretix