VYPR
Vendor

Intevation

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2025-30342MedMar 21, 2025
    risk 0.35cvss 5.4epss 0.00

    An XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor is shown that allows one to format the submitted text. This allows insertion of various HTML elements. When trying to insert a SCRIPT element,…

  • CVE-2025-30344MedMar 21, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100…

  • CVE-2025-30345LowMar 21, 2025
    risk 0.23cvss 3.5epss 0.00

    An issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify the name of the chat. Some HTML elements such as SCRIPT are filtered, whereas others are not. In most cases, HTML entities are encoded…

  • CVE-2025-30343LowMar 21, 2025
    risk 0.20cvss 3.0epss 0.00

    A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in folders. The interface allows users to download a ZIP archive that contains all files in a folder and its subfolders. If an attacker specifies the…