2025.10.0
8 years ago
2 days ago
Known vulnerabilities in the pretix package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
pretix is a Reinventing presales, one ticket at a time Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the email template rendering logic. An attacker can cause arbitrary HTML content to be injected into outgoing emails by supplying specially crafted input in the attendee name field. This can be abused to manipulate the appearance of emails, making malicious content appear credible and potentially facilitating phishing attacks. How to fix Cross-site Scripting (XSS)? Upgrade | [,2025.7.2)[2025.8.0,2025.8.1)[2025.9.0,2025.9.1) |