2026.1.2
8 years ago
2 days ago
Known vulnerabilities in the pretalx package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
pretalx is a Conference organisation: CfPs, scheduling, much more Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the organizer search. An attacker can execute arbitrary JavaScript code in the context of an organizer's browser by injecting malicious payloads into fields such as submission titles, speaker display names, or user names/emails, which are rendered using How to fix Cross-site Scripting (XSS)? Upgrade | [,2026.1.0) |