Cross-Site Scripting in Indico Event Management System
CVE-2026-107397
4.4MEDIUM
What is CVE-2026-107397?
Indico's event management system, utilizing Flask-Multipass, is susceptible to a cross-site scripting vulnerability. Users authorized to create content, including the ability to edit event minutes, can introduce malicious HTML. This can lead to the execution of attacker-controlled scripts in the browsers of users viewing the event minutes, particularly during concurrent editing sessions. The issue has been rectified in version 3.3.13.
Affected Version(s)
indico < 3.3.13
