Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Indico
(Cern)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2023-07-21 | CVE-2023-37901 | Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerability in confirmation prompts commonly used when deleting content from Indico. Exploitation requires someone with at least submission privileges (such as a speaker) and then someone else to attempt to delete this content. Considering that event organizers may want to delete suspicious-looking content when spotting it, there is a non-negligible risk of such an attack to... | Indico | 5.4 | ||
2021-04-07 | CVE-2021-30185 | CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link. | Indico | 7.5 |