← Back

Xo Server

xo-server

Vendor: Xen Orchestra • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xen Orchestra
2Xo Server
Xo Web
Jun 17, 2026
Jul 12, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none...Show more
Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as VMs, Backups, Audit, Users, and Groups.Show less