An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the submitted text. This allows insertion of various HTML elements. When trying to insert a SCRIPT element, it is properly encoded when reflected; however, adding attributes to links is possible, which allows the injection of JavaScript via the onmouseover attribute and others. When a user moves the mouse over such a prepared link, JavaScript is executed in that user's session.
History

Thu, 27 Mar 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Openslides
Openslides openslides
CPEs cpe:2.3:a:openslides:openslides:*:*:*:*:*:*:*:*
Vendors & Products Openslides
Openslides openslides

Fri, 21 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Mar 2025 06:00:00 +0000

Type Values Removed Values Added
Description An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the submitted text. This allows insertion of various HTML elements. When trying to insert a SCRIPT element, it is properly encoded when reflected; however, adding attributes to links is possible, which allows the injection of JavaScript via the onmouseover attribute and others. When a user moves the mouse over such a prepared link, JavaScript is executed in that user's session.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-21T15:03:49.963Z

Reserved: 2025-03-21T00:00:00.000Z

Link: CVE-2025-30342

cve-icon Vulnrichment

Updated: 2025-03-21T15:03:20.536Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-21T06:15:26.510

Modified: 2025-03-27T13:35:33.940

Link: CVE-2025-30342

cve-icon Redhat

No data.