CVE-2023-23126

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:connectwise:automate:2022.11:*:*:*:*:*:*:*

History

21 Nov 2024, 07:45

Type Values Removed Values Added
References () https://github.com/l00neyhacker/CVE-2023-23126 - Third Party Advisory () https://github.com/l00neyhacker/CVE-2023-23126 - Third Party Advisory

07 Nov 2023, 04:07

Type Values Removed Values Added
Summary ** DISPUTED ** Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack. Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

Information

Published : 2023-02-01 14:15

Updated : 2024-11-21 07:45


NVD link : CVE-2023-23126

Mitre link : CVE-2023-23126

CVE.ORG link : CVE-2023-23126


JSON object : View

Products Affected

connectwise

  • automate
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames