Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-289f-922v-5266

Опубликовано: 07 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.

The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.

EPSS

Процентиль: 25%
0.00083
Низкий

8.6 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.6
nvd
около 2 лет назад

The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.

EPSS

Процентиль: 25%
0.00083
Низкий

8.6 High

CVSS3

Дефекты

CWE-89