VYPR
Medium severity6.1NVD Advisory· Published Apr 29, 2026· Updated Apr 30, 2026

CVE-2025-56537

CVE-2025-56537

Description

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual network template parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

OpenNebula 6.10.0.1 and earlier versions contain a stored XSS vulnerability in the virtual network template parameter, fixed in version 7.0.

Vulnerability

Overview

CVE-2025-2025-56537 is a stored cross-site scripting (XSS) vulnerability in OpenNebula 6.10.0.1 and earlier versions allows an attacker to inject arbitrary web scripts or HTML via a crafted payload into the virtual network template parameter [1][2]. The vulnerability resides in the opennebula-sunstone component, which is the web-based user interface for OpenNebula [2].

Exploitation

An attacker with access to create or modify virtual network templates can inject a malicious payload, such as <image src =q onerror=prompt(8)> into the template parameter [2]. When an administrator or administrator views the affected template in the Sunstone interface, the injected script executes in the context of their browser session [2]. No authentication bypass is required, but the attacker must have privileges to edit virtual network templates [2].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session [1][2]. This can lead to session hijacking, defacement, or theft of sensitive information displayed in the Sunstone interface [2]. The CVSS v3 score of 6.1 (Medium) reflects the need for user interaction and the potential for partial impact on confidentiality and integrity [1].

Mitigation

The vulnerability is fixed in OpenNebula version 7.0 (Phoenix) and later [1][2]. Users running OpenNebula 6.10.0.1 or earlier should upgrade to version 7.0 or newer to remediate the issue [1][2]. No workarounds are documented in the available references.

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*range: <7.0.0
    • (no CPE)range: <=6.10.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.