Actions
Bug #16258
closedPotential XSS in OpenVPN Widget
Start date:
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
25.07
Release Notes:
Default
Affected Version:
Affected Architecture:
Description
The OpenVPN widget prints the name of OpenVPN clients and shared key servers without encoding, leading to a potential XSS.
To reproduce, set the name of an OpenVPN client instance or shared key server instance to Blah<script>alert('XSS')</script>
and then add the OpenVPN widget to the Dashboard.
Actions