PT-2025-37075 · Cern+1 · Indico+1
Thiefmaster
·
Published
2025-09-10
·
Updated
2025-09-10
·
CVE-2025-59035
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Indico versions prior to 3.3.8
Description:
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. A Cross-Site-Scripting issue exists when rendering LaTeX math code in contribution or abstract descriptions.
Recommendations:
Update to Indico version 3.3.8.
As a workaround, restrict content creation to trusted users.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flask-Multipass
Indico