From 8bd78eefcfb22b2651018253635c9f2dc69e794e Mon Sep 17 00:00:00 2001 From: Mira Weller Date: Fri, 19 Jun 2026 13:22:19 +0200 Subject: [PATCH] [SECURITY] Fix reflected XSS in redirection page (CVE-2026-57533) --- .../base/templates/pretixbase/redirect.html | 3 +- src/pretix/helpers/templatetags/wrap_in.py | 33 +++++++++++++++++++ 2 files changed, 35 insertions(+), 1 deletion(-) create mode 100644 src/pretix/helpers/templatetags/wrap_in.py diff --git a/src/pretix/base/templates/pretixbase/redirect.html b/src/pretix/base/templates/pretixbase/redirect.html index 6c8404b4dd..62048c1227 100644 --- a/src/pretix/base/templates/pretixbase/redirect.html +++ b/src/pretix/base/templates/pretixbase/redirect.html @@ -2,13 +2,14 @@ {% load i18n %} {% load rich_text %} {% load static %} +{% load wrap_in %} {% block title %}{% trans "Redirect" %}{% endblock %} {% block content %}

{% trans "Redirect" %}

- {% blocktrans trimmed with host=""|add:hostname|add:""|safe %} + {% blocktrans trimmed with host=hostname|wrap_in:'strong' %} The link you clicked on wants to redirect you to a destination on the website {{ host }}. {% endblocktrans %} {% blocktrans trimmed %} diff --git a/src/pretix/helpers/templatetags/wrap_in.py b/src/pretix/helpers/templatetags/wrap_in.py new file mode 100644 index 0000000000..e08bd2c909 --- /dev/null +++ b/src/pretix/helpers/templatetags/wrap_in.py @@ -0,0 +1,33 @@ +# +# This file is part of pretix (Community Edition). +# +# Copyright (C) 2014-2020 Raphael Michel and contributors +# Copyright (C) 2020-today pretix GmbH and contributors +# +# This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General +# Public License as published by the Free Software Foundation in version 3 of the License. +# +# ADDITIONAL TERMS APPLY: Pursuant to Section 7 of the GNU Affero General Public License, additional terms are +# applicable granting you additional permissions and placing additional restrictions on your usage of this software. +# Please refer to the pretix LICENSE file to obtain the full terms applicable to this work. If you did not receive +# this file, see . +# +# This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied +# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more +# details. +# +# You should have received a copy of the GNU Affero General Public License along with this program. If not, see +# . +# +import logging + +from django import template +from django.utils.html import format_html + +register = template.Library() +logger = logging.getLogger(__name__) + + +@register.filter +def wrap_in(content, tag_name): + return format_html(f'<{tag_name}>{{}}', content)