vendor:
Royal TS/X
by:
Jakub Palaczynski
8.1
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Royal TS/X
Affected Version From: Royal TS v5 Beta
Affected Version To: Royal TSX v4 Beta
Patch Exists: YES
Related CWE: CVE-2018-18865
CPE: a:code4ward:royal_tsx
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Royal TS/X – Information Disclosure
Any third party web application can steal credentials created in Royal TS/X when browser extension is enabled. Browser extension communicates using websockets (default TCP port 54890) and websockets do not use any validation to verify origin of the request.
Mitigation:
Disable the browser extension or use a firewall to block the websocket communication.