A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with another vulnerability in the platform (CVE-2023-39420, which grants access to hardcoded credentials) to carry the attack without having assigned credentials. 
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Bitdefender

Published: 2023-09-07T12:25:42.733Z

Updated: 2023-09-07T12:25:42.733Z

Reserved: 2023-08-01T15:26:26.149Z


Link: CVE-2023-39424

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-09-07T13:15:08.933

Modified: 2023-09-12T00:09:32.553


Link: CVE-2023-39424

JSON object: View

cve-icon Redhat Information

No data.