« Volver al listado

Cern

Cern Indico: vulnerabilidades y CVE

Cern Indico tiene 11 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses4
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-33046Alta (7.7)1.0%—23 mar 2026
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to vulnerabilities in TeXLive and obscure LaTeX syntax that allowed…
CVE-2026-28352Media (6.5)0.36%—27 feb 2026
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event series is missing an access check,…
CVE-2026-25739Media (5.4)0.29%—19 feb 2026
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain file types as…
CVE-2026-25738Media (6.9)0.33%—19 feb 2026
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to server-side request forgery. Indico makes outgoing requests to…
CVE-2025-59035Media (5.4)0.21%—10 sept 2025
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, there is a Cross-Site-Scripting vulnerability when rendering LaTeX math code in…
CVE-2025-59034Media (4.3)0.26%—10 sept 2025
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retrieve profile details…
CVE-2025-53640Media (5.3)0.60%—14 jul 2025
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in…
CVE-2024-50633Alta (7.5)0.63%—16 ene 2025
A Broken Object Level Authorization (BOLA) vulnerability in Indico through 3.3.5 allows attackers to read information by sending a crafted POST request to the component /api/principals. NOTE: this is disputed by the…
CVE-2024-45399Media (6.1)0.38%—4 sept 2024
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indico prior to version 3.3.4, corresponding to Flask-Multipass prior to version 0.5.5, there is a…
CVE-2023-37901Media (5.4)0.52%—21 jul 2023
Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerability in confirmation prompts commonly used when deleting content from Indico. Exploitation requires…
CVE-2021-30185Alta (7.5)1.0%—7 abr 2021
CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.

Otros productos de Cern