PT-2026-108199 · Indico · Indico
CVE-2026-107397
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Indico versions prior to 3.3.13
Description
Users with content creation privileges, such as speakers capable of creating minutes, can store crafted HTML within event minutes. When concurrent edits occur on the same minutes, the minute editor conflict UI can execute attacker-controlled scripts in the viewer's browser within the Indico origin.
Recommendations
Update to version 3.3.13.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Indico