VYPR
Medium severity6.1NVD Advisory· Published Apr 29, 2026· Updated Apr 30, 2026

CVE-2025-56536

CVE-2025-56536

Description

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OpenNebula versions prior to 7.0 contain a stored XSS via user information parameter allows arbitrary script execution.

A stored cross-site scripting (XSS) vulnerability exists in the OpenNebula cloud management platform. The flaw resides in the opennebula-sunstone component, where the user information parameter does not properly sanitize user-supplied input. This allows an attacker to inject malicious web scripts or HTML into the application's data store [2].

Exploitation requires an authenticated attacker to set the user information field, for example with a payload like <image src =q onerror=prompt(8)>. When other users view the affected profile or administrative interface, the injected script executes in the context of their browser session. No additional user interaction beyond viewing the crafted profile is needed [2].

An attacker who successfully exploits this vulnerability can execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, credential theft, or defacement of the OpenNebula user interface. The CVSS v3 base score of 6.1 (Medium) reflects the need for low-privilege access and the potential for significant confidentiality and integrity impact [1].

The vulnerability affects OpenNebula versions before 7.0. The fix is to upgrade to OpenNebula version 7.0 or later, where input sanitization is applied. Users of earlier versions should update as soon as possible to mitigate the risk [2].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*range: <7.0.0
    • (no CPE)range: = 6.10.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.