PT-2026-108199 · Indico · Indico

CVE-2026-107397

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Indico versions prior to 3.3.13
Description Users with content creation privileges, such as speakers capable of creating minutes, can store crafted HTML within event minutes. When concurrent edits occur on the same minutes, the minute editor conflict UI can execute attacker-controlled scripts in the viewer's browser within the Indico origin.
Recommendations Update to version 3.3.13.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107397
GHSA-CW24-X4MJ-FW3Q

Affected Products

Indico