Executive brief
pretix is an open-source ticket sales and event management platform. A security flaw exists where an attacker can inject malicious content into the page shown when a user is being redirected to an external site. While technical safeguards limit the ability to run malicious code, this vulnerability can be used to create convincing phishing pages to trick users into revealing sensitive information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the redirection component of pretix. The application fails to properly sanitize input when displaying a warning page for untrusted external redirections, allowing an attacker to inject malicious HTML content. Although the impact of script execution is mitigated by a strong Content-Security-Policy (CSP), the vulnerability can still be leveraged for phishing or UI redressing. The attack requires a user to interact with a specially crafted link. The issue is fixed in versions 2026.3.4, 2026.4.4, and 2026.5.2.
Affected products
- rami.io pretix < 2026.3.4, 2026.4.0 to < 2026.4.4, 2026.5.0 to < 2026.5.2
Timeline
- 2026-06-25: disclosed
- 2026-06-25: patched
- 2026-06-25: advisory