PT-2023-26171 · Indico · Indico

Thiefmaster

·

Publicado

2023-07-21

·

Atualizado

2023-07-31

·

CVE-2023-37901

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Indico versions prior to 3.2.6
Description There is a Cross-Site-Scripting issue in confirmation prompts used when deleting content from Indico. Exploitation requires someone with at least submission privileges and then someone else to attempt to delete this content. Event organizers may want to delete suspicious-looking content, posing a non-negligible risk of such an attack succeeding. This risk could be further increased with social engineering pointing the victim towards this content.
Recommendations For versions prior to 3.2.6, update to Indico 3.2.6 as soon as possible. For users who cannot upgrade, only let trustworthy users manage categories, create events, or upload materials.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37901
GHSA-FMQQ-25X9-C6HM
PYSEC-2023-129

Produtos afetados

Indico