Description
Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://github.com/l00neyhacker/CVE-2023-23126 |
|
History
Wed, 25 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T10:28:40.804Z
Reserved: 2023-01-11T00:00:00.000Z
Link: CVE-2023-23126
Updated: 2024-08-02T10:28:40.804Z
Status : Modified
Published: 2023-02-01T14:15:09.617
Modified: 2024-11-21T07:45:52.250
Link: CVE-2023-23126
No data.
OpenCVE Enrichment
No data.
Weaknesses