PT-2025-2876 · Indico · Indico
Thiefmaster
·
Published
2025-01-10
·
Updated
2025-01-21
·
CVE-2024-50633
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Indico versions 3.2.9 through 3.3.5
Description
A Broken Object Level Authorization (BOLA) issue allows attackers to read or access sensitive information by sending a crafted POST request to the "/api/principals" component. The supplier disputes this issue, stating that the product is designed to allow all users to retrieve certain information about other user accounts.
Recommendations
For Indico versions 3.2.9 through 3.3.5, as a temporary workaround, consider restricting access to the "/api/principals" component until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Indico