CVE-2023-23128: ConnectWise
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Control-Allow-Origin wildcarding to support product functionality, and that there is no risk from this behavior. The vulnerability report is thus not valid.
Affected products
- ConnectWise ConnectWise: version 22.8.10013.8329 only
Published 2023-02-01. Last modified 2026-06-17.