User Detail Exposure Vulnerability in Indico Event Management System by Indico
CVE-2025-59034
What is CVE-2025-59034?
A flaw exists in the Indico event management system due to a broken access check in a legacy API that allows attackers to retrieve the profile details of other users without necessary administrative permissions. This vulnerability affects versions prior to 3.3.8 of Indico, which relies on Flask-Multipass for multi-backend authentication. To safeguard sensitive user data, it is crucial for users to upgrade to Indico version 3.3.8 immediately. As a temporary measure, users can restrict access to the vulnerable API through server configuration settings.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
indico < 3.3.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
