NA

CVE-2023-39421

Published: 07/09/2023 Updated: 12/09/2023
CVSS v3 Base Score: 7.7 | Impact Score: 4 | Exploitability Score: 3.1
VMScore: 0

Vulnerability Summary

The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.

Vulnerable Product Search on Vulmon Subscribe to Product

resortdata internet reservation module next generation 5.4.1.23