CVE-2023-23126: Medium severity connectwise vulnerability
DISPUTED Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23126?
CVE-2023-23126 is classified as a low severity vulnerability related to Clickjacking.
How do I fix CVE-2023-23126?
To mitigate CVE-2023-23126, ensure that a proper Content-Security-Policy HTTP response header is implemented.
What type of attack does CVE-2023-23126 refer to?
CVE-2023-23126 refers to a Clickjacking attack that can manipulate users into performing unintended actions.
Which version of ConnectWise Automate is affected by CVE-2023-23126?
CVE-2023-23126 affects ConnectWise Automate version 2022.11.
Is there a vendor response to CVE-2023-23126?
Yes, the vendor claims that a Content-Security-Policy HTTP response header is in place to protect against this vulnerability.