Description


Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can create content, including speakers who can create minutes, can store crafted HTML in event minutes. When concurrent edits are made to the same minutes, the minute editor conflict UI can execute attacker-controlled script in the viewer's browser in the Indico origin. This issue is fixed in version 3.3.13.

Related CPE's


Could not find any relations

Weaknesses



CWE-79

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

4.4 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-08T21:17:51.937Z

11 hours ago

Last modified

2026-10-08T21:35:53.890Z

11 hours ago