Executive Summary



This vulnerability is currently undergoing analysis and not all information is available. Please check back soon to view the completed vulnerability summary
Informations
Name CVE-2025-53640 First vendor Publication 2025-07-14
Vendor Cve Last vendor Modification 2025-07-14

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Starting in version 2.2 and prior to version 3.3.7, an endpoint used to display details of users listed in certain fields (such as ACLs) could be misused to dump basic user details (such as name, affiliation and email) in bulk. Version 3.3.7 fixes the issue. Owners of instances that allow everyone to create a user account, who wish to truly restrict access to these user details, should consider restricting user search to managers. As a workaround, it is possible to restrict access to the affected endpoints (e.g. in the webserver config), but doing so would break certain form fields which could no longer show the details of the users listed in those fields, so upgrading instead is highly recommended.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-53640

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-639 Access Control Bypass Through User-Controlled Key
50 % CWE-200 Information Exposure

Sources (Detail)

https://docs.getindico.io/en/stable/config/settings/#ALLOW_PUBLIC_USER_SEARCH
https://docs.getindico.io/en/stable/installation/upgrade
https://github.com/indico/indico/releases/tag/v3.3.7
https://github.com/indico/indico/security/advisories/GHSA-q28v-664f-q6wj
Source Url

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2025-07-15 00:20:36
  • First insertion