CVE-2025-13742
published 2025-11-27CVE-2025-13742: Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.15%
5.0th percentile
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pretix | pretix | — | — |
| pretix | pretix | — | — |
| pretix | pretix | >= 1.0.0 < 2025.7.0 | 2025.7.0 |
| pretix | pretix | >= 1.0.0 < 2025.7.2 | 2025.7.2 |
| pretix | pretix | >= 1.0.0 < 2025.7.3 | 2025.7.3 |
| pretix | pretix | >= 2025.7.0 < 2025.8.0 | 2025.8.0 |
| pretix | pretix | >= 2025.8.0 < 2025.9.0 | 2025.9.0 |
| pretix | pretix | >= 2025.8.0 < 2025.8.2 | 2025.8.2 |
| pretix | pretix | >= 2025.9.0 < 2025.10.0 | 2025.10.0 |
| pretix | pretix | >= 2025.9.0 < 2025.9.2 | 2025.9.2 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.02.4LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mm6-624x-fqrr: Emails sent by pretix can utilize placeholders that will be filled with customer data
ghsa_unreviewed·2025-11-27
CVE-2025-13742 [LOW] CWE-116 GHSA-2mm6-624x-fqrr: Emails sent by pretix can utilize placeholders that will be filled with customer data
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing.
GHSA
pretix has Email Content Injection Through Maliciously Formatted Names
ghsa·2025-11-27
CVE-2025-13742 [LOW] CWE-116 pretix has Email Content Injection Through Maliciously Formatted Names
pretix has Email Content Injection Through Maliciously Formatted Names
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-27
Published