PT-2025-2876 · Indico · Indico

·

CVE-2024-50633

·

Published

2025-01-10

·

Updated

2026-07-07

CVSS v3.1

0.0

None

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Name of the Vulnerable Software and Affected Versions Indico versions 3.2.9 through 3.3.5
Description A Broken Object Level Authorization (BOLA) issue allows attackers to read or access sensitive information by sending a crafted POST request to the "/api/principals" component. The supplier disputes this issue, stating that the product is designed to allow all users to retrieve certain information about other user accounts.
Recommendations For Indico versions 3.2.9 through 3.3.5, as a temporary workaround, consider restricting access to the "/api/principals" component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-50633
GHSA-3WG7-R7Q5-R2JF
PYSEC-2026-1459

Affected Products

Indico