NA

CVE-2023-39423

Published: 07/09/2023 Updated: 12/09/2023
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.

Vulnerable Product Search on Vulmon Subscribe to Product

resortdata internet reservation module next generation 5.3.2.15