Описание
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:resortdata:internet_reservation_module_next_generation:5.3.2.15:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00083
Низкий
8.6 High
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 8.6
github
около 2 лет назад
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.
EPSS
Процентиль: 25%
0.00083
Низкий
8.6 High
CVSS3
9.1 Critical
CVSS3
Дефекты
CWE-89