CVE-2023-39423 Information
Sep 08, 2023
cve
Description
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs among other features. By using a UNION SQL operator an attacker can leak the sessions table obtain the currently valid sessions and impersonate a currently logged-in user.