Product:

Indico

(Cern)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 2
Date Id Summary Products Score Patch Annotated
2023-07-21 CVE-2023-37901 Indico is an open source a general-purpose, web based event management tool. There is a Cross-Site-Scripting vulnerability in confirmation prompts commonly used when deleting content from Indico. Exploitation requires someone with at least submission privileges (such as a speaker) and then someone else to attempt to delete this content. Considering that event organizers may want to delete suspicious-looking content when spotting it, there is a non-negligible risk of such an attack to... Indico 5.4
2021-04-07 CVE-2021-30185 CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link. Indico 7.5