"-Synchronized-Data."

This commit is contained in:
CVE Team 2023-02-03 07:00:43 +00:00
parent edb17a203a
commit 96028621ec
No known key found for this signature in database
GPG Key ID: E3252B3D49582C98

View File

@ -34,7 +34,7 @@
"description_data": [
{
"lang": "eng",
"value": "Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions."
"value": "** DISPUTED ** Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended actions. NOTE: the vendor's position is that a Content-Security-Policy HTTP response header is present to block this attack."
}
]
},