Unrated severityNVD Advisory· Published Sep 7, 2023· Updated Sep 26, 2024
Use of Hard-coded Credentials in multiple /irmdata/api/ endpoints
CVE-2023-39422
Description
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.