CVE-2019-16517

CRITICAL

ConnectWise Control <19.3.25270.7185 - SSRF

Title source: llm
STIX 2.1

Description

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with the server APIs and perform administrative actions, without the victim's knowledge.

Scores

CVSS v3 9.8
EPSS 0.0133
EPSS Percentile 67.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-346
Status published
Products (1)
connectwise/control 19.3.25270.7185
Published Jan 23, 2020
Tracked Since Feb 18, 2026