CVE-2025-30345
CVSS 3.1 Score 4.1 of 10 (medium)
Details
Published Mar 21, 2025
Updated: Mar 27, 2025
CWE ID 116
CWE ID 79
Summary
CVE-2025-30345 is an vulnerability affecting OpenSlides before version 4.2.5. During chat creation, users can specify chat names, and while some HTML elements are filtered, others, such as SCRIPT tags, are not. This inconsistency can potentially be exploited by attackers to manipulate the website layout. However, it's unlikely that victims would unintentionally interact with deleted chats or messages.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Openslides