PT-2023-26171 · Indico · Indico
Thiefmaster
·
Published
2023-07-21
·
Updated
2023-07-31
·
CVE-2023-37901
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Indico versions prior to 3.2.6
Description
There is a Cross-Site-Scripting issue in confirmation prompts used when deleting content from Indico. Exploitation requires someone with at least submission privileges and then someone else to attempt to delete this content. Event organizers may want to delete suspicious-looking content, posing a non-negligible risk of such an attack succeeding. This risk could be further increased with social engineering pointing the victim towards this content.
Recommendations
For versions prior to 3.2.6, update to Indico 3.2.6 as soon as possible.
For users who cannot upgrade, only let trustworthy users manage categories, create events, or upload materials.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Indico