Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-16517

Опубликовано: 23 янв. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:connectwise:control:19.3.25270.7185:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00224
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-346

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.

EPSS

Процентиль: 45%
0.00224
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-346