CVE-2025-3840 | Saviynt OVA based Connect up to RHEL-8.x_SC2.0-Client-3.0 Login Form action cross site scripting
A vulnerability classified as problematic has been found in Saviynt OVA based Connect. Affected is an unknown function of the component Login Form. The manipulation of the argument action leads to cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2025-3840. It is possible to launch the attack remotely. There is no exploit available.