Cross-Site Scripting Vulnerability in OpenNebula by OpenNebula Systems
CVE-2025-56535

6.1MEDIUM

Key Information:

Vendor
CVE Published:
29 April 2026

What is CVE-2025-56535?

A cross-site scripting (XSS) vulnerability exists in OpenNebula version 6.10.0.1, allowing attackers to execute arbitrary web scripts or HTML by injecting malicious payloads into the zone attribute parameter. This can lead to unauthorized actions within the browser session of the user, compromising the integrity and confidentiality of the application. It is crucial for users to apply necessary security updates to mitigate potential attacks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.