OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
References
Link | Resource |
---|---|
https://openvpn.net/vpn-server-resources/release-notes/#openvpn-access-server-2-9-5 | Release Notes Vendor Advisory |
Configurations
Information
Published : 2021-09-23 08:15
Updated : 2021-09-29 13:21
NVD link : CVE-2021-3824
Mitre link : CVE-2021-3824
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
openvpn
- openvpn_access_server