Back to CVE List

CVE-2026-18029

Vulnerability Description

Our payment integration with GiroCheckout did not properly validate
payment status responses. An attacker could use a successful payment
status response from one payment and supply it to the system for a
different payment, gaining access to multiple valid tickets with only
one payment.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-841
Source
NVD
Vendor
pretix GmbH
Product
pretix-girosolution

External References

Discussion (0)

Add Comment

No comments yet. Be the first!