CVE-2023-39422
07.09.2023, 13:15
The/irmdata/api/ endpoints exposed by theIRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.Enginsight
Vendor | Product | Version |
---|---|---|
resortdata | internet_reservation_module_next_generation | - |
𝑥
= Vulnerable software versions