Vulnerabilities > CVE-2023-39423 - Unspecified vulnerability in Resortdata Internet Reservation Module Next Generation 5.3.2.15

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
resortdata
critical

Summary

The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.

Vulnerable Configurations

Part Description Count
Application
Resortdata
1