CVE-2019-16517 - ConnectWise Control - Cross-Origin Resource Sharing (CORS) Misconfiguration

Опубликовано: 22 Август 2026
на канале: Huntress
817
0

Product: ConnectWise Control

Status: Mitigated

Bishop Fox Summary: Both the ConnectWise Control cloud and customer instances were affected by a CORS misconfiguration, which reflected the Origin provided by incoming requests. This allowed JavaScript running on any domain to interact with both the Control cloud and customer Control server APIs and perform administrative actions, such as signing session identifiers, without the victim's knowledge.
https://cve.mitre.org/cgi-bin/cvename...