A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the title of a file or folder as a relative or absolute path (e.g., ../../../etc/passwd), the ZIP archive generated for download converts that title into a path. Depending on the extraction tool used by the user, this might overwrite files locally outside of the chosen directory.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 21 Mar 2025 06:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the title of a file or folder as a relative or absolute path (e.g., ../../../etc/passwd), the ZIP archive generated for download converts that title into a path. Depending on the extraction tool used by the user, this might overwrite files locally outside of the chosen directory. | |
Weaknesses | CWE-24 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-21T00:00:00.000Z
Updated: 2025-03-21T14:01:52.519Z
Reserved: 2025-03-21T00:00:00.000Z
Link: CVE-2025-30343

Updated: 2025-03-21T14:01:47.961Z

Status : Received
Published: 2025-03-21T06:15:26.700
Modified: 2025-03-21T06:15:26.700
Link: CVE-2025-30343

No data.