The RDPData.dll file exposes the... CVE-2023-39423

- AV AC AU C I A
发布: 2023-09-07
修订: 2023-09-12

The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息