Vulnerabilities > CVE-2023-39422 - Unspecified vulnerability in Resortdata Internet Reservation Module Next Generation
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |