User Detail Exposure Vulnerability in Indico Event Management System by Indico
CVE-2025-59034

4.3MEDIUM

Key Information:

Vendor

Indico

Status
Vendor
CVE Published:
10 September 2025

What is CVE-2025-59034?

A flaw exists in the Indico event management system due to a broken access check in a legacy API that allows attackers to retrieve the profile details of other users without necessary administrative permissions. This vulnerability affects versions prior to 3.3.8 of Indico, which relies on Flask-Multipass for multi-backend authentication. To safeguard sensitive user data, it is crucial for users to upgrade to Indico version 3.3.8 immediately. As a temporary measure, users can restrict access to the vulnerable API through server configuration settings.

Affected Version(s)

indico < 3.3.8

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59034 : User Detail Exposure Vulnerability in Indico Event Management System by Indico