CVE-2023-39422
EUVD-2023-4314607.09.2023, 13:15
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| resortdata | internet_reservation_module_next_generation | - |
𝑥
= Vulnerable software versions