logo

How to guarantee a speaker gig: Hack the system. Literally

ID: 2cb747fb-705f-5ed2-a71d-ab6aabb89e82

STIX ID: report--2cb747fb-705f-5ed2-a71d-ab6aabb89e82

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

...
...

A security researcher discovered CVE-2026-41241, a stored XSS vulnerability in pretalx (conference management software) that could execute attacker-controlled JavaScript in organizer interfaces, expose CSRF tokens, and enable organizer-level actions such as modifying submissions or impersonating staff; the flaw was responsibly disclosed and fixed in pretalx 2026.1.0, and while many public deployments exist the researcher found no evidence of malicious real-world exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.