CVE-2025-56536
Description
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OpenNebula versions prior to 7.0 contain a stored XSS via user information parameter allows arbitrary script execution.
A stored cross-site scripting (XSS) vulnerability exists in the OpenNebula cloud management platform. The flaw resides in the opennebula-sunstone component, where the user information parameter does not properly sanitize user-supplied input. This allows an attacker to inject malicious web scripts or HTML into the application's data store [2].
Exploitation requires an authenticated attacker to set the user information field, for example with a payload like <image src =q onerror=prompt(8)>. When other users view the affected profile or administrative interface, the injected script executes in the context of their browser session. No additional user interaction beyond viewing the crafted profile is needed [2].
An attacker who successfully exploits this vulnerability can execute arbitrary JavaScript in the victim's browser. This can lead to session hijacking, credential theft, or defacement of the OpenNebula user interface. The CVSS v3 base score of 6.1 (Medium) reflects the need for low-privilege access and the potential for significant confidentiality and integrity impact [1].
The vulnerability affects OpenNebula versions before 7.0. The fix is to upgrade to OpenNebula version 7.0 or later, where input sanitization is applied. Users of earlier versions should update as soon as possible to mitigate the risk [2].
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*range: <7.0.0
- (no CPE)range: = 6.10.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- opennebula.io/opennebula-7/nvdProduct
News mentions
0No linked articles in our index yet.