In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade indico
to version 2.1.10, 2.2.3 or higher.
indico is a conference lifecycle management and meeting/lecture scheduling tool.
Affected versions of this package are vulnerable to Information Exposure. Malicious users can run unsafe LaTeX
commands on the server, which allows them to read local files (e.g. indico.conf
). As far as is known it is not possible to write files or execute code using this vulnerability.