Vulnerability Description
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Resortdata | Internet Reservation Module Next Generation | - |
Related Weaknesses (CWE)
References
- https://bitdefender.com/blog/labs/check-out-with-extra-charges-vulnerabilities-iThird Party Advisory
- https://bitdefender.com/blog/labs/check-out-with-extra-charges-vulnerabilities-iThird Party Advisory
FAQ
What is CVE-2023-39422?
CVE-2023-39422 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side,...
How severe is CVE-2023-39422?
CVE-2023-39422 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-39422?
Check the references section above for vendor advisories and patch information. Affected products include: Resortdata Internet Reservation Module Next Generation.