A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the title of a file or folder as a relative or absolute path (e.g., ../../../etc/passwd), the ZIP archive generated for download converts that title into a path. Depending on the extraction tool used by the user, this might overwrite files locally outside of the chosen directory.
CVE ID: CVE-2025-30343
CVSS Base Severity: LOW
CVSS Base Score: 3.0
CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
Vendor: Intevation
Product: OpenSlides
EPSS Score: 0.18% (probability of being exploited)
EPSS Percentile: 40.88% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)