← Back to browse · API

CVE-2023-39424

Severity
CRITICAL
CVSS
9.9
EPSS
0.00737
Risk score
39.86
CISA KEV
No
PoC
No
Published
2023-09-07
Modified
2024-09-26
First seen
2026-08-07
Aliases
EUVD-2023-43148, GHSA-28PF-JJ6H-H694
Products
Resort Data Processing, Inc.:IRM Next Generation 1.0.0.0
Sources
euvd EUVD-2023-43148

Description

A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication to be exploited but can be paired with another vulnerability in the platform (CVE-2023-39420, which grants access to hardcoded credentials) to carry the attack without having assigned credentials.

References