CVE-2019-16512: XSS
Published Jan 23, 2020
·Updated
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is stored XSS in the Appearance modifier.
Affected Software
1 affected component
ConnectWise Control=19.3.25270.7185
Event History
Jan 23, 2020
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16512?
CVE-2019-16512 is a vulnerability discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
2
What is the severity of CVE-2019-16512?
The severity of CVE-2019-16512 is medium with a CVSS score of 4.8.
3
What is the nature of the vulnerability in CVE-2019-16512?
CVE-2019-16512 is a stored cross-site scripting (XSS) vulnerability in the Appearance modifier of ConnectWise Control.
4
Which version of ConnectWise Control is affected by CVE-2019-16512?
The vulnerability affects ConnectWise Control version 19.3.25270.7185.
5
How can I fix CVE-2019-16512?
To fix CVE-2019-16512, it is recommended to update ConnectWise Control to a patched version provided by the vendor.