Open XDMoD是Center for Computational Research开源的一款用于管理高性能计算资源的开源工具。 Open XDMoD 11.0.3之前版本存在访问控制错误漏洞,该漏洞源于访问控制逻辑缺陷,允许攻击者提交特制的HTTPS POST请求设置用于授权决策的会话变量,可能导致绕过数据访问限制并查看其他用户的计算作业效率指标。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45777 | Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Inject | |
| CVE-2026-45779 | Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromise | |
| CVE-2026-45778 | Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset |
No comments yet