PT-2021-22009 · Openvpn · Openvpn Access Server
Published
2021-09-23
·
Updated
2021-09-29
·
CVE-2021-3824
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenVPN Access Server versions 2.9.0 through 2.9.4
Description:
The issue allows remote attackers to inject arbitrary web script or HTML via the web login page URL.
Recommendations:
For OpenVPN Access Server versions 2.9.0 through 2.9.4, consider restricting access to the web login page until a fix is available. As a temporary workaround, avoid using the web login page URL to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openvpn Access Server