CVE-2023-27891: Rami Pretix

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.

Affected products

  • Rami Pretix: from 1.16.0, before 4.15.1 (fixed in 4.15.1); version 4.16.0 only; version 4.17.0 only

Published 2023-03-06. Last modified 2026-06-17.