CVE-2023-23126

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
References
Link Resource
https://github.com/l00neyhacker/CVE-2023-23126 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:connectwise:automate:2022.11:*:*:*:*:*:*:*

History

07 Nov 2023, 04:07

Type Values Removed Values Added
Summary ** DISPUTED ** Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack. Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

08 Feb 2023, 20:38

Type Values Removed Values Added
First Time Connectwise
Connectwise automate
CPE cpe:2.3:a:connectwise:automate:2022.11:*:*:*:*:*:*:*
CWE CWE-1021
References (MISC) https://github.com/l00neyhacker/CVE-2023-23126 - (MISC) https://github.com/l00neyhacker/CVE-2023-23126 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

03 Feb 2023, 07:15

Type Values Removed Values Added
Summary Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. ** DISPUTED ** Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

01 Feb 2023, 14:45

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-01 14:15

Updated : 2024-04-11 01:18


NVD link : CVE-2023-23126

Mitre link : CVE-2023-23126

CVE.ORG link : CVE-2023-23126


JSON object : View

Products Affected

connectwise

  • automate
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames