CVE-2024-50633None· 0.0▾ TwilightPoC availableIndico Insecure Access
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 2.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.6%
1 GitHub repo
A Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9 allows attackers to access sensitive information via sending a crafted POST request to the component /api/principals.
indico >= 3.2.9, < 3.3.3Upgrade to a patched release:
indico 3.3.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-53640MediumIndico vulnerability allows attackers to bulk dump user details
CVE-2026-33046HighIndico discloses local files resulting in Remote Code Execution through LaTeX injection
CVE-2026-28352Medium· 6.5Indico has a missing access check in the event series management API
CVE-2026-25739Medium· 5.4Indico Affected by Cross-Site-Scripting via material uploads
CVE-2026-25738MediumIndico has Server-Side Request Forgery (SSRF) in multiple places
CVE-2025-59035Medium· 4.6Indico vulnerable to Cross-Site Scripting via LaTeX math code