VYPR
Unrated severityNVD Advisory· Published Sep 7, 2023· Updated Sep 26, 2024

Use of Hard-coded Credentials in RDPWin.dll

CVE-2023-39421

Description

The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.