CVE-2021-3824: XSS
Published Sep 23, 2021
·Updated
OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web login page URL.
Affected Software
1 affected component
OpenVPN OpenVPN Access Server>=2.9.0<=2.9.4
Event History
Sep 23, 2021
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this OpenVPN Access Server vulnerability?
The vulnerability ID of this OpenVPN Access Server vulnerability is CVE-2021-3824.
2
What is the severity of CVE-2021-3824?
The severity of CVE-2021-3824 is medium.
3
How does CVE-2021-3824 affect OpenVPN Access Server?
CVE-2021-3824 allows remote attackers to inject arbitrary web script or HTML via the web login page URL on OpenVPN Access Server 2.9.0 through 2.9.4.
4
How can I fix CVE-2021-3824 in OpenVPN Access Server?
To fix CVE-2021-3824 in OpenVPN Access Server, you should update to version 2.9.5 or later.
5
Where can I find more information about CVE-2021-3824?
You can find more information about CVE-2021-3824 in the release notes of OpenVPN Access Server 2.9.5.