CVE-2025-13742
MEDIUMDescription
Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing.
Is your site exposed to CVE-2025-13742?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| pretix | pretix |
| pretix | pretix |
| pretix | pretix |
References
Other References
Frequently Asked Questions
What is CVE-2025-13742? +
How severe is CVE-2025-13742? +
What products are affected by CVE-2025-13742? +
How do I check if I'm vulnerable to CVE-2025-13742? +
Related Vulnerabilities
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and …
Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to …
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
During an address list folding when a separating comma ends up on a folded line and that line is to …
A vulnerability exists in PX Backup whereby sensitive information may be logged under specific conditions.
Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. …