CVE-2020-26280 describes a persistent Cross-Site Scripting (XSS) vulnerability in OpenSlides version 3.2, a web-based presentation and assembly system. Due to insufficient user input validation and escaping, attackers can inject arbitrary JavaScript code into rich text fields, which then executes when other users view the affected text. This vulnerability carries a high CVSS score of 8.9, indicating a significant risk, as it can lead to session hijacking, manipulation of votes, or general disruption of meetings. While the vulnerability is easily exploitable with low attack complexity, there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding it. The issue was patched in OpenSlides version 3.3.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2CPE matchmatch criteria | cpe:2.3:a:openslides:openslides:3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.