Security Advisory

CVE-2023-23126

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-02-01 00:00:00
Last updated 2024-08-02 10:28:40
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.