PT-2026-2401 · Prowise · Prowise Reflect
Rik Lutz
·
Publicado
2026-01-13
·
Atualizado
2026-01-30
·
CVE-2022-50925
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Prowise Reflect version 1.0.9
Description
Prowise Reflect version 1.0.9 has a remote keystroke injection issue. An exposed WebSocket on port 8082 allows attackers to send keyboard events. Malicious web pages can be created to inject keystrokes, enabling attackers to open applications and type arbitrary text by sending specific WebSocket messages.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Origin Validation Error
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Prowise Reflect