Remote Code Injection in OpenVPN Access Server Web Login Interface
CVE-2021-3824
6.1MEDIUM
What is CVE-2021-3824?
The OpenVPN Access Server versions 2.9.0 through 2.9.4 are susceptible to a vulnerability that allows remote attackers to inject arbitrary web scripts or HTML code via the web login page URL. This flaw could potentially enable attackers to execute malicious scripts in the context of a user’s session, compromising the integrity and confidentiality of sensitive information. Users of affected versions are advised to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
OpenVPN Access Server 2.9.0 through 2.9.4