CVE-2017-1000065

MEDIUM

OpenMediaVault 2.1 - XSS

Title source: llm

Description

Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.

Scores

CVSS v3 6.1
EPSS 0.0035
EPSS Percentile 57.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
openmediavault/openmediavault
n/a/n/a
Published Jul 17, 2017
Tracked Since Feb 18, 2026