PT-2025-29511 · Unknown+1 · Flask-Multipass+1
Rafaelcorvino1
·
Published
2025-07-14
·
Updated
2025-09-15
·
CVE-2025-53640
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Indico versions 2.2 through 3.3.7
Description:
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. An endpoint used to display details of users listed in certain fields could be misused to dump basic user details (such as name, affiliation, and email) in bulk.
Recommendations:
Upgrade to version 3.3.7 or later.
Consider restricting user search to managers.
Restrict access to the affected endpoints in the webserver configuration.
Exploit
Fix
IDOR
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flask-Multipass
Indico