
Stored XSS exploit for OpenNebula 6.10.0.1 via crafted payload in virtual network template parameter. Includes PoC and fix guidance for upgrading to version 7.0.
Exploit Title : OpenNebula 6.10.0.1 - Stored XSS (Cross-site Scripting) in virtual network template
Exploit Author : Mark Artamonov
Vendor Homepage : https://opennebula.io/
Tested Version : OpenNebula 6.10.0.1
Affected Versions : OpenNebula < 7.0
Affected Component : opennebula-sunstone
CVE ID : CVE-2025-56537
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual network template parameter.
<image src =q onerror=prompt(8)>

Upgrade to OpenNebula >=7.0.