Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cj53-rx7h-6vm4

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 9.8

Описание

Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific WebSocket messages.

Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific WebSocket messages.

EPSS

Процентиль: 5%
0.00023
Низкий

8.6 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 9.8
nvd
25 дней назад

Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific WebSocket messages.

EPSS

Процентиль: 5%
0.00023
Низкий

8.6 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-346