PT-2025-29511 · Unknown+1 · Flask-Multipass+1

Rafaelcorvino1

·

Published

2025-07-14

·

Updated

2025-09-15

·

CVE-2025-53640

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Indico versions 2.2 through 3.3.7
Description: Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. An endpoint used to display details of users listed in certain fields could be misused to dump basic user details (such as name, affiliation, and email) in bulk.
Recommendations: Upgrade to version 3.3.7 or later. Consider restricting user search to managers. Restrict access to the affected endpoints in the webserver configuration.

Exploit

Fix

IDOR

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-53640
GHSA-Q28V-664F-Q6WJ

Affected Products

Flask-Multipass
Indico