Intevation OpenSlides
cpe:2.3:a:openslides:openslides:*:*:*:*:*:*:*
- 4.2.4
A directory traversal vulnerability has been identified in OpenSlides versions prior to 4.2.5. This issue allows files to be uploaded to OpenSlides meetings and organized into folders. Users can download a ZIP archive containing all files in a selected folder and its subfolders. However, if an attacker includes a relative or absolute path in the title of a file or folder, the ZIP archive will convert that title into a path. Depending on the extraction tool used, this could overwrite files locally outside of the chosen directory.
Exploitation of this vulnerability could lead to unintentional overwriting of files on the user's local system, potentially causing data loss or disruption.
To reproduce this vulnerability, upload a file to an OpenSlides meeting and organize it into a folder. Then, specify the title of a file or folder as a relative or absolute path, such as '../../../etc/passwd'. When the ZIP archive is downloaded and extracted, the specified path will be converted into a file path, potentially overwriting files outside of the selected directory, depending on the extraction tool used.
Users can update to OpenSlides version 4.2.5, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.