Our payment integration with GiroCheckout did not properly validate
payment status responses. An attacker could use a successful payment
status response from one payment and supply it to the system for a
different payment, gaining access to multiple valid tickets with only
one payment.
payment status responses. An attacker could use a successful payment
status response from one payment and supply it to the system for a
different payment, gaining access to multiple valid tickets with only
one payment.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://pretix.eu/about/en/blog/20260728-release-2026-6-1/ |
|
History
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pretix Gmbh
Pretix Gmbh pretix-girosolution |
|
| Vendors & Products |
Pretix Gmbh
Pretix Gmbh pretix-girosolution |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment. | |
| Title | Insufficient validation of payment status in pretix-girosolution | |
| Weaknesses | CWE-841 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: rami.io
Published:
Updated: 2026-07-28T12:36:18.719Z
Reserved: 2026-07-28T07:28:43.937Z
Link: CVE-2026-18029
Updated: 2026-07-28T12:32:47.166Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T20:34:55Z
Weaknesses