An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escalate privileges to root.
References
| Link | Resource |
|---|---|
| http://openmediavault.com | Product |
| https://gist.github.com/xbz0n/4b98e9291ddd5bb5e6232609e36b2082 | Exploit Third Party Advisory |
| https://xbz0n.sh/blog/CVE-2025-50674 | Exploit Mitigation Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-08-22 16:15
Updated : 2025-09-12 19:42
NVD link : CVE-2025-50674
Mitre link : CVE-2025-50674
CVE.ORG link : CVE-2025-50674
JSON object : View
Products Affected
openmediavault
- openmediavault
