Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-30344


An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ depending on whether a user exists in the system. The timing discrepancy stems from the omitted hashing of the password (e.g., more than 100 milliseconds).


Published

2025-03-21T06:15:26.900

Last Modified

2025-03-27T14:40:42.177

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-208
  • Type: Primary
    CWE-203

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openslides openslides < 4.2.5 Yes

References