Cross-site request forgery (CSRF) vulnerability in the Admin web interface in OpenVPN Access Server before 1.8.5 allows remote attackers to hijack the authentication of administrators for requests that create administrative users.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2631
http://secunia.com/advisories/52802
http://openvpn.net/index.php/access-server/download-openvpn-as-sw/531-release-notes-v185.html