Advisories

Prowise Reflect v1.0.9 - Remote Keystroke Injection

Go Back
severity
high
date
Affecting
  • Prowise Reflect V1.0.9

CWE
  • CWE-346 Origin Validation Error
CVSS
8.6
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
Rik Lutz
Description
Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific WebSocket messages.