A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with another vulnerability in the platform (CVE-2023-39420, which grants access to hardcoded credentials) to carry the attack without having assigned credentials. 
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Bitdefender

Published: 2023-09-07T12:25:42.733Z

Updated: 2024-08-02T18:10:20.808Z

Reserved: 2023-08-01T15:26:26.149Z

Link: CVE-2023-39424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-09-07T13:15:08.933

Modified: 2023-09-12T00:09:32.553

Link: CVE-2023-39424

cve-icon Redhat

No data.