Executive brief
Open XDMoD is a tool used to analyze performance metrics for high-performance computing (HPC) environments. A security flaw allows a logged-in user to inject malicious code into their profile and use the password reset system to send a dangerous link to other users. If a victim clicks the link, the attacker could steal their login credentials or take over their account, potentially compromising sensitive research data or system access.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Open XDMoD's password reset functionality. An authenticated attacker can inject a malicious JavaScript payload into their own user profile; when the attacker subsequently triggers a password reset, the system generates an email containing a link to an HTML page that fails to sanitize the profile data. When a victim visits this page, the payload executes in their browser context. This can lead to session hijacking, credential theft, and full account takeover. The vulnerability is patched in version 11.0.3.
Affected products
- ubccr Open XDMoD < 11.0.3
Timeline
- 2026-04-06: disclosed: Reported privately
- 2026-05-12: patched: Patched in version 11.0.3
- 2026-06-05: advisory: NVD publication date