First published: Thu Jan 23 2020(Updated: )
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ConnectWise Control | =19.3.25270.7185 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-16517 is critical with a CVSS score of 9.8.
CVE-2019-16517 is a vulnerability in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185 that allows JavaScript running on any domain to interact with server APIs and perform administrative actions.
CVE-2019-16517 impacts ConnectWise Control by allowing unauthorized JavaScript from any domain to interact with server APIs and perform administrative actions.
Yes, a fix for CVE-2019-16517 is available. It is recommended to update ConnectWise Control to a version that addresses the CORS misconfiguration vulnerability.
More information about CVE-2019-16517 can be found in the following references: [link 1], [link 2], [link 3].