Vulnerabilities > CVE-2023-39422 - Unspecified vulnerability in Resortdata Internet Reservation Module Next Generation

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
resortdata
critical

Summary

The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.

Vulnerable Configurations

Part Description Count
Application
Resortdata
1