-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from missing HTML escaping in email preview rendering. The commit diff shows critical additions of django.utils.html.escape() in functions handling placeholder samples. These functions construct HTML elements (buttons/spans) using user-controlled placeholder values without proper sanitization, enabling XSS via malicious HTML injection. The high confidence comes from direct correlation between the patched lines and the vulnerability description's focus on email preview HTML sanitization.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| pretix | pip | < 2024.7.1 | 2024.7.1 |
Ongoing coverage of React2Shell