CVE-2025-56534 - Vulnerability Analysis
MediumCVSS: 6.1Last Updated: April 29, 2026
OpenNebula - Stored XSS
Published: April 29, 2026Updated: April 29, 2026PoC AvailableRemote Exploitable
Overview
OpenNebula v6.10.0.1 contains a stored XSS vulnerability caused by improper sanitization in the custom authenticator driver, letting attackers execute arbitrary web scripts or HTML via crafted payloads.
Severity & Score
Severity: Medium
CVSS Score: 6.1
Impact
Attackers can execute arbitrary scripts in users' browsers, potentially stealing session data or performing actions on behalf of users.
Mitigation
Update to the latest version of OpenNebula.
References
Related Resources
Details
- CVE ID
- CVE-2025-56534
- Severity
- Medium
- CVSS Score
- 6.1
- Type
- stored_xss
- Status
- new
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N