l00neyhacker/CVE-2023-23126

l00neyhacker/CVE-2023-23126

Releases0
CVE-2023-23126

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.