HIGH🇵🇱 Wersja polska

CVE-2026-45778

CVSS 8.6v4.0pub. 2026-06-05upd. 2026-06-10

OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious JavaScript into their Open XDMoD user profile and abuse the password reset functionality to email a link to an HTML page, which when visited by the victim, reflects and executes the unsanitized payload in the victim's browser, potentially leading to credential capture and Open XDMoD account takeover. All deployments of Open XDMoD prior to 11.0.3 are impacted. This issue was reported privately on 2026-04-06, and at this time there is no evidence that this vulnerability has been exploited in the wild. The vulnerability was patched in Open XDMoD 11.0.3 on 2026-05-12. As a workaround, apply the patch manually.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Buffalo Open Xdmod

    APP
    Buffalo
    < 11.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-45777CRITICAL9.3PL ✓same product

RCE poprzez command injection w Open XDMoD (wersje 9.5.0–11.0.2)

CVE-2026-45779CRITICAL9.3PL ✓same product

SQL Injection w Open XDMoD — nieuwierzytelniony dostęp do bazy danych

CVE-2018-16988CRITICAL9.8PL ✓same product

Open XDMoD – obejście uwierzytelnienia przez słaby mechanizm resetowania hasła

CVE-2018-16961HIGH7.5same product

An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal...

CVE-2026-45776MEDIUM5.3same product

OpenXDMoD to otwarty framework do zbierania i analizowania metryk HPC. Przed wersją 11.0.3 usterka w logice ko...