Vulnerabilities > CVE-2023-23126 - Improper Restriction of Rendered UI Layers or Frames vulnerability in Connectwise Automate 2022.11
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |