PT-2023-26171 · Indico · Indico

Thiefmaster

·

Published

2023-07-21

·

Updated

2023-07-31

·

CVE-2023-37901

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Indico versions prior to 3.2.6
Description There is a Cross-Site-Scripting issue in confirmation prompts used when deleting content from Indico. Exploitation requires someone with at least submission privileges and then someone else to attempt to delete this content. Event organizers may want to delete suspicious-looking content, posing a non-negligible risk of such an attack succeeding. This risk could be further increased with social engineering pointing the victim towards this content.
Recommendations For versions prior to 3.2.6, update to Indico 3.2.6 as soon as possible. For users who cannot upgrade, only let trustworthy users manage categories, create events, or upload materials.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-37901
GHSA-FMQQ-25X9-C6HM
PYSEC-2023-129

Affected Products

Indico