- Description
- Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) endpoint servers to inject arbitrary web script or HTML via the RelayState parameter
- Source
- security@openvpn.net
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 6.4
- Impact score
- 2.7
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- security@openvpn.net
- CWE-79
- Hype score
- Not currently trending
CVE-2025-50055 Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assert… https://t.co/6ftJC9Dj5q
@CVEnew
27 Oct 2025
246 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-50055: SAML Injection in OpenVPN Access Server, high rating❗️ The vulnerability allows an attacker to perform JavaScript injection via SAML relaystate, potentially leading to RCE. Search at https://t.co/hv7QKSqxTR: 👉 Link: https://t.co/90v5A8EFnm https://t.co/Tu
@Netlas_io
8 Aug 2025
646 Impressions
2 Retweets
11 Likes
2 Bookmarks
0 Replies
0 Quotes