properly validate payment status responses. An attacker could use a
successful payment status response from one payment and supply it to the
system for a different payment, gaining access to multiple valid
tickets with only one payment.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://pretix.eu/about/en/blog/20260625-release-2026-5-2/ |
|
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pretix
Pretix pretix-computop |
|
| Vendors & Products |
Pretix
Pretix pretix-computop |
Thu, 25 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Jun 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. | |
| Title | Insufficient validation of payment status in pretix-computop | |
| Weaknesses | CWE-841 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: rami.io
Published:
Updated: 2026-06-25T15:14:14.673Z
Reserved: 2026-06-24T16:01:54.416Z
Link: CVE-2026-13223
Updated: 2026-06-25T15:14:12.103Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:37:38Z