PT-2025-48262 · Pretix · Pretix
Jan Roring
·
Published
2025-11-27
·
Updated
2025-12-30
·
CVE-2025-13742
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
pretix (affected versions not specified)
Description
The software allows the use of placeholders in email templates that are populated with customer data, such as the attendee's name. If a customer's name contains HTML or Markdown formatting, this formatting is rendered in the final email. While a strict allow list approach prevents cross-site scripting (XSS) or similar attacks, this can be exploited to manipulate emails, potentially enabling phishing attacks by making user-provided content appear trustworthy. The issue involves the rendering of potentially malicious formatting within the
name placeholder when constructing emails.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pretix