Executive brief
Venueless, a platform for virtual events, contains a security flaw in its social login feature. An attacker can create a malicious link that appears to be a legitimate login page but redirects the user to a fraudulent website after they sign in. This can be used in phishing campaigns to trick users into visiting malicious sites while believing they are still on a trusted domain.
Technical details
An open redirect vulnerability (CWE-601) exists in the social login component of Venueless. The application fails to properly validate the destination URL in the redirect parameter after a user completes the social authentication process. A remote attacker can craft a URL that leverages the trusted domain of the Venueless instance to redirect authenticated users to an arbitrary external site. Exploitation requires the attacker to have low privileges and for a victim to interact with the malicious link. The issue has been addressed in commit d27864a7.
Affected products
- pretix Venueless < d27864a7 (git)
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory
- 2026-06-22: patched