CVE-2023-44463
02.10.2023, 20:15
An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.Enginsight
Vendor | Product | Version |
---|---|---|
rami | pretix | 𝑥 < 2023.7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References