PT-2025-12395 · Unknown · Openslides

Published

2025-03-21

·

Updated

2025-03-27

·

CVE-2025-30343

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSlides versions prior to 4.2.5
Description A directory traversal issue was discovered in OpenSlides. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the title of a file or folder as a relative or absolute path (e.g., ../../../etc/passwd), the ZIP archive generated for download converts that title into a path. Depending on the extraction tool used by the user, this might overwrite files locally outside of the chosen directory.
Recommendations For versions prior to 4.2.5, update to version 4.2.5 or later to resolve the issue. As a temporary workaround, consider avoiding the use of relative or absolute paths in file or folder titles to minimize the risk of exploitation. Restrict access to sensitive files and folders to prevent potential overwriting of files locally outside of the chosen directory.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-30343

Affected Products

Openslides