VYPR
Unrated severityNVD Advisory· Published Sep 7, 2023· Updated Sep 26, 2024

Improper Neutralization of Special Elements used in an SQL Command in RDPData.dll

CVE-2023-39423

Description

The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.