Vulnerability Description
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Resortdata | Internet Reservation Module Next Generation | 5.3.2.15 |
Related Weaknesses (CWE)
References
- https://bitdefender.com/blog/labs/check-out-with-extra-charges-vulnerabilities-iThird Party Advisory
- https://bitdefender.com/blog/labs/check-out-with-extra-charges-vulnerabilities-iThird Party Advisory
FAQ
What is CVE-2023-39423?
CVE-2023-39423 is a vulnerability with a CVSS score of 8.6 (HIGH). The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the curren...
How severe is CVE-2023-39423?
CVE-2023-39423 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-39423?
Check the references section above for vendor advisories and patch information. Affected products include: Resortdata Internet Reservation Module Next Generation.