pretix
cpe:2.3:a:pretix:pretix:*:*:*:*:*:*:*
- >= 4.16.0, < 2026.1.1
A vulnerability exists in the pretix newsletter plugin, allowing for the exfiltration of sensitive system information through improperly sanitized email placeholders. Users with control over email templates could exploit this to access confidential data such as database passwords and API keys. The issue arises from a flaw in the plugin's placeholder handling, which failed to fully implement existing security measures. As a precaution, users are advised to rotate any passwords and API keys stored in their pretix configuration file.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including system configuration details, database passwords, and API keys.
Users of the pretix newsletter plugin should update to version 2.0.1 or 1.6.3, both of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.