CVE-2026-107397

medium

Description

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can create content, including speakers who can create minutes, can store crafted HTML in event minutes. When concurrent edits are made to the same minutes, the minute editor conflict UI can execute attacker-controlled script in the viewer's browser in the Indico origin. This issue is fixed in version 3.3.13.

References

https://github.com/indico/indico/security/advisories/GHSA-cw24-x4mj-fw3q

https://github.com/indico/indico/releases/tag/v3.3.13

https://github.com/indico/indico/pull/7619

https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95253

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 3.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:P/A:N

Severity: Low

CVSS v3

Base Score: 4.4

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00233