PT-2020-9828 · Connectwise · Connectwise Control

Matt Hamilton

·

Published

2020-01-23

·

Updated

2020-01-24

·

CVE-2019-16512

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ConnectWise Control version 19.3.25270.7185
Description An issue was discovered in ConnectWise Control, where there is stored XSS in the Appearance modifier.
Recommendations For version 19.3.25270.7185, update to a newer version that contains a fix for this issue, as using an outdated version may pose a security risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16512

Affected Products

Connectwise Control