CVE-2025-59034Medium· 4.3▾ SunlitIndico may disclose unauthorized user details access via legacy API
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.3%
A legacy API to retrieve user details could be misused to retrieve profile details of other users without having admin permissions due to a broken access check.
You should to update to Indico 3.3.8 as soon as possible. See the docs for instructions on how to update.
It is possible to restrict access to the affected API (e.g. in the webserver config) which is most likely unused anyway and thus will not break anything.
If you have any questions or comments about this advisory:
indico < 3.3.8Upgrade to a patched release:
indico 3.3.8Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59035Medium· 4.6Indico vulnerable to Cross-Site Scripting via LaTeX math code
CVE-2026-33046HighIndico discloses local files resulting in Remote Code Execution through LaTeX injection
CVE-2026-28352Medium· 6.5Indico has a missing access check in the event series management API
CVE-2026-25739Medium· 5.4Indico Affected by Cross-Site-Scripting via material uploads
CVE-2026-25738MediumIndico has Server-Side Request Forgery (SSRF) in multiple places
CVE-2025-53640MediumIndico vulnerability allows attackers to bulk dump user details