Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-13602

PUBLISHED 01.07.2026

CNA: rami.io

Session takeover vulnerability

Обновлено: 01.07.2026
We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: * The payment integration plugins Stripe (included in the core system), pretix-mollie, pretix-oppwa, pretix-bitpay, pretix-payone, pretix-secuconnect, pretix-sofort, and pretix-saferpay contain a code path that is intended for the transport of session parameters from a tab with isolated cookies (e.g. in the pretix widget) to a new tab. For this purpose, a set of session parameters is cryptographically signed and then passed to the new tab as a URL parameter. The plugins perform no further validation of the session parameters, other than the cryptographic signature being valid. This is fixed with the releases issued today by strictly validating that no session parameters outside of the scope of the respective plugin may be set. * An unrelated feature in the core system is used to generate redirect links that obfuscate any Referer headers for outgoing links to prevent leakage of secrets in URLs. This redirect page also requires cryptographically signed parameters. Unfortunately, it uses the same key and salt for the signature as the previously mentioned feature in the payment integration plugins. A motivated attacker with access to at least one event in the backend can trick the system into cryptographically signing arbitrary content using specially crafted links. In combination with the previous issue, the attacker could use this to set and modify arbitrary parameters on their user session by injecting the signed parameters into the feature of the payment providers. This is fixed with the releases issued today by using different salts for the signature for each plugin and feature. * A third, unrelated feature in the core system is used for admin users to act on behalf of another user, mostly for debugging purposes. With being able to insert arbitrary parameters into a session, an attacker can abuse this feature to change their session from their actual user to any user in the system by guessing a valid user ID. This is fixed with the release today by requiring unguessable information to be contained in the session of the user to switch to.

CWE

Идентификатор Описание
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-323 Nonces should be used for the present occasion and only once.

CVSS

Оценка Severity Версия Базовый вектор
7.7 HIGH 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U

Доп. Информация

Product Status

pretix
Product: pretix
Vendor: pretix
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 4.14.0 до 2026.3.5 affected
Наблюдалось в версиях от 2026.4.0 до 2026.4.5 affected
Наблюдалось в версиях от 2026.5.0 до 2026.5.3 affected
pretix-mollie
Product: pretix-mollie
Vendor: pretix
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 2.5.7 affected
pretix-oppwa
Product: pretix-oppwa
Vendor: pretix
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.4.4 affected
pretix-bitpay
Product: pretix-bitpay
Vendor: pretix
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.5.3 affected
pretix-payone
Product: pretix-payone
Vendor: pretix
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.4.3 affected
pretix-secuconnect
Product: pretix-secuconnect
Vendor: pretix
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.0.4 affected
pretix-sofort
Product: pretix-sofort
Vendor: pretix
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.4.2 affected
pretix-saferpay
Product: pretix-saferpay
Vendor: pretix
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 1.6.3 affected
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 01.07.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none no total 2.0.3 01.07.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.