CVE-2013-2692
Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0018 (0.2%)
Percentile: 39.4%
EPSS: 2026-05-06
Affects
openvpn:openvpn_access_serverTechnical description
Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users.
Published: 5/13/2014, 2:55:09 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://openvpn.net/index.php/access-server/download-openvpn-as-sw/531-release-notes-v185.html
- http://osvdb.org/93111
- http://secunia.com/advisories/52802
- http://openvpn.net/index.php/access-server/download-openvpn-as-sw/531-release-notes-v185.html
- http://osvdb.org/93111
- http://secunia.com/advisories/52802