CVE-2022-50925: Prowise Reflect v1.0.9 - Remote Keystroke Injection
Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific WebSocket messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50925?
CVE-2022-50925 is categorized as a critical vulnerability due to its potential for remote exploitation.
How do I fix CVE-2022-50925?
To resolve CVE-2022-50925, it is recommended to upgrade to a patched version of Prowise Reflect that addresses the remote keystroke injection issue.
What impact does CVE-2022-50925 have on users?
CVE-2022-50925 allows attackers to send unauthorized keystrokes, potentially compromising user data and system integrity.
Which versions of Prowise Reflect are affected by CVE-2022-50925?
Prowise Reflect version 1.0.9 is known to be affected by CVE-2022-50925.
Is CVE-2022-50925 exploitable remotely?
Yes, CVE-2022-50925 can be exploited remotely through an exposed WebSocket on port 8082.