CVE-2026-18029
Vulnerability Description
Our payment integration with GiroCheckout did not properly validate
payment status responses. An attacker could use a successful payment
status response from one payment and supply it to the system for a
different payment, gaining access to multiple valid tickets with only
one payment.
payment status responses. An attacker could use a successful payment
status response from one payment and supply it to the system for a
different payment, gaining access to multiple valid tickets with only
one payment.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-841
Source
NVD
Vendor
pretix GmbH
Product
pretix-girosolution
Discussion (0)
Add Comment
No comments yet. Be the first!