Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj8v-mj23-mw67

Опубликовано: 01 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions.

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions.

EPSS

Процентиль: 51%
0.00283
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.1
nvd
около 3 лет назад

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack.

EPSS

Процентиль: 51%
0.00283
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021