Description
An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.
Severity (CVSS)
| Base score | 5.1 |
|---|---|
| Severity | Medium |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-601 — CWE-601 URL redirection to untrusted site ('open redirect')
Affected products
| Vendor | Product | Versions |
|---|---|---|
| pretix | Venueless | 0.0.0 to <d27864a7 |
References
Generated from the official CVE List on 22 Jun 2026 14:43 UTC.