CVE-2025-56537
Description
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual network template parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
OpenNebula 6.10.0.1 and earlier versions contain a stored XSS vulnerability in the virtual network template parameter, fixed in version 7.0.
Vulnerability
Overview
CVE-2025-2025-56537 is a stored cross-site scripting (XSS) vulnerability in OpenNebula 6.10.0.1 and earlier versions allows an attacker to inject arbitrary web scripts or HTML via a crafted payload into the virtual network template parameter [1][2]. The vulnerability resides in the opennebula-sunstone component, which is the web-based user interface for OpenNebula [2].
Exploitation
An attacker with access to create or modify virtual network templates can inject a malicious payload, such as <image src =q onerror=prompt(8)> into the template parameter [2]. When an administrator or administrator views the affected template in the Sunstone interface, the injected script executes in the context of their browser session [2]. No authentication bypass is required, but the attacker must have privileges to edit virtual network templates [2].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session [1][2]. This can lead to session hijacking, defacement, or theft of sensitive information displayed in the Sunstone interface [2]. The CVSS v3 score of 6.1 (Medium) reflects the need for user interaction and the potential for partial impact on confidentiality and integrity [1].
Mitigation
The vulnerability is fixed in OpenNebula version 7.0 (Phoenix) and later [1][2]. Users running OpenNebula 6.10.0.1 or earlier should upgrade to version 7.0 or newer to remediate the issue [1][2]. No workarounds are documented in the available references.
AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*range: <7.0.0
- (no CPE)range: <=6.10.0.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- opennebula.io/opennebula-7/nvdProduct
News mentions
0No linked articles in our index yet.