Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T10:28:40.804Z

Reserved: 2023-01-11T00:00:00

Link: CVE-2023-23126

cve-icon Vulnrichment

Updated: 2024-08-02T10:28:40.804Z

cve-icon NVD

Status : Modified

Published: 2023-02-01T14:15:09.617

Modified: 2024-11-21T07:45:52.250

Link: CVE-2023-23126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.