PT-2025-2876 · Indico · Indico
CVSS v3.1
0.0
None
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Indico versions 3.2.9 through 3.3.5
Description
A Broken Object Level Authorization (BOLA) issue allows attackers to read or access sensitive information by sending a crafted POST request to the "/api/principals" component. The supplier disputes this issue, stating that the product is designed to allow all users to retrieve certain information about other user accounts.
Recommendations
For Indico versions 3.2.9 through 3.3.5, as a temporary workaround, consider restricting access to the "/api/principals" component until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Indico