Home

Description

An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaVault 7.4.17 allowing local authenticated attackers to escalate privileges to root.

PUBLISHED Reserved 2025-06-16 | Published 2025-08-22 | Updated 2025-08-26 | Assigner mitre

References

openmediavault.com

gist.github.com/xbz0n/4b98e9291ddd5bb5e6232609e36b2082

xbz0n.sh/blog/CVE-2025-50674

cve.org (CVE-2025-50674)

nvd.nist.gov (CVE-2025-50674)

Download JSON