Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) endpoint servers to inject arbitrary web script or HTML via the RelayState parameter
History

Thu, 30 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Openvpn
Openvpn openvpn
Openvpn openvpn Access Server
Vendors & Products Openvpn
Openvpn openvpn
Openvpn openvpn Access Server

Mon, 27 Oct 2025 13:45:00 +0000

Type Values Removed Values Added
Description Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) endpoint servers to inject arbitrary web script or HTML via the RelayState parameter
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published: 2025-10-27T13:39:43.652Z

Updated: 2025-10-30T18:23:58.634Z

Reserved: 2025-06-11T17:29:58.718Z

Link: CVE-2025-50055

cve-icon Vulnrichment

Updated: 2025-10-30T18:23:54.490Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-27T14:15:40.687

Modified: 2025-10-30T19:16:24.857

Link: CVE-2025-50055

cve-icon Redhat

No data.