CVE-2025-30345

CVSS 3.1 Score 4.1 of 10 (medium)

Details

Published Mar 21, 2025
Updated: Mar 27, 2025
CWE ID 116
CWE ID 79

Summary

CVE-2025-30345 is an vulnerability affecting OpenSlides before version 4.2.5. During chat creation, users can specify chat names, and while some HTML elements are filtered, others, such as SCRIPT tags, are not. This inconsistency can potentially be exploited by attackers to manipulate the website layout. However, it's unlikely that victims would unintentionally interact with deleted chats or messages.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share