CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-8113

High Severity
SVRS
53/100

CVSSv3
5.4/10

EPSS
0.00103/1

CVE-2024-8113: Stored XSS vulnerability in pretix event settings. Malicious organizers can inject HTML into email previews, affecting users up to version 2024.7.0. While pretix's Content Security Policy mitigates script execution, a future CSP bypass could enable severe exploitation. SOCRadar Vulnerability Risk Score (SVRS) is 53, indicating a moderate risk. This security flaw could lead to impersonation of staff or other organizers if combined with other vulnerabilities. Immediate patching is recommended to prevent potential future attacks. Ignoring this vulnerability puts pretix installations at risk.

No tags available
CVSS:3.1
AV:N
AC:L
PR:L
UI:R
S:C
C:L
I:L
A:N
2024-08-23

2024-09-12
Eye Icon
SOCRadar
AI Insight

Description

CVE-2024-8113 is a stored cross-site scripting (XSS) vulnerability in the organizer and event settings of pretix versions up to 2024.7.0. This vulnerability allows malicious event organizers to inject HTML tags into email previews on the settings page. While the default Content Security Policy (CSP) of pretix prevents the execution of attacker-provided scripts, making exploitation unlikely, a CSP bypass could allow attackers to impersonate other organizers or staff users.

Key Insights

  • SVRS of 0: The SVRS score of 0 indicates that this vulnerability is not considered critical and does not require immediate action.
  • Exploitation unlikely: The default CSP of pretix prevents the execution of attacker-provided scripts, making exploitation unlikely.
  • Potential for impersonation: If combined with a CSP bypass, this vulnerability could be used to impersonate other organizers or staff users.

Mitigation Strategies

  • Update pretix: Update pretix to version 2024.7.1 or later to address this vulnerability.
  • Review CSP settings: Review the CSP settings of your pretix installation to ensure that they are configured correctly.
  • Monitor for suspicious activity: Monitor your pretix installation for any suspicious activity, such as unauthorized changes to event settings or emails.

Additional Information

  • Threat Actors/APT Groups: No specific threat actors or APT groups have been identified as actively exploiting this vulnerability.
  • Exploit Status: No active exploits have been published for this vulnerability.
  • CISA Warnings: The Cybersecurity and Infrastructure Security Agency (CISA) has not issued a warning for this vulnerability.
  • In the Wild: This vulnerability is not known to be actively exploited by hackers.

If you have any additional questions regarding this incident, you can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information.

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

No news found for this CVE

Social Media

CVE-2024-8113 Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The def… https://t.co/0SycBc8gkk
0
0
0

Affected Software

No affected software found for this CVE

References

ReferenceLink
655498C3-6EC5-4F0B-AEA6-853B334D05A6https://pretix.eu/about/en/blog/20240823-release-2024-7-1/

CWE Details

CWE IDCWE NameDescription
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence