CVE-2023-23126

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
References
Link Resource
https://github.com/l00neyhacker/CVE-2023-23126 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:connectwise:automate:2022.11:*:*:*:*:*:*:*

History

07 Nov 2023, 04:07

Type Values Removed Values Added
Summary ** DISPUTED ** Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack. Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

Information

Published : 2023-02-01 14:15

Updated : 2024-08-02 11:15


NVD link : CVE-2023-23126

Mitre link : CVE-2023-23126

CVE.ORG link : CVE-2023-23126


JSON object : View

Products Affected

connectwise

  • automate
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames