Unrated severityNVD Advisory· Published Sep 7, 2023· Updated Sep 26, 2024
Use of Hard-coded Credentials in RDPWin.dll
CVE-2023-39421
Description
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.
Affected products
1- Range: 5.4.1.23
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.