Showing 1 vulnerability on this page for pretix-payone

Signals CISA KEV Ransomware Nuclei
pretix vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Session takeover vulnerability

We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: * The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay contain a code path that is intended for the transport of session parameters from a tab with isolated cookies (e.g. in the pretix widget) to a new ta

CWE-20CWE-323Jul 1, 2026
CVSS7.7v4.0EPSS0.271%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX