CVE 4.3 MEDIUM

Indico may disclose unauthorized user details access via legacy API_CVE-2025-59034

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check. Users should to update to Indico 3.3.8 as soon as possible. As a workaround, it is possible to restrict access to the affected API (e.g. in the webserver config).

Basic Information

ID CVE-2025-59034
Source GitHub_M
Published Sep 10, 2025 at 16:01

Affected Product

Vendor indico
Product indico
Version < 3.3.8
Affected Versions indico indico < 3.3.8

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.