CVE-2026-41241
pretalx vulnerable to stored cross-site scripting in organizer search typeahead
8.7
HIGH
CVSS 3.1
EPSS 0.17%
描述
pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display names, and user names/emails into the result dropdown using innerHTML string interpolation. Any user who controls one of those fields (which includes any registered user whose display name is looked up by an administrator) could include HTML or JavaScript that would execute in an organiser's browser when the organiser's search query matched the malicious record. This vulnerability is fixed in 2026.1.0.
如何修補 CVE-2026-41241
要修補 CVE-2026-41241,請將受影響套件升級到下列已修補版本。
- —升級至 2026.1.0 或更新版本
- —升級至 2026.1.0 或更新版本
CVE-2026-41241 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2026.1.0
- from 0, < 2026.1.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.7 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |