Resortdata
Resortdata Internet Reservation Module Next Generation: vulnerabilidades y CVE
Resortdata Internet Reservation Module Next Generation tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-39424 | Alta (8.8) | 0.99% | — | 7 sept 2023 | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with… |
| CVE-2023-39423 | Crítica (9.1) | 0.56% | — | 7 sept 2023 | The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions… |
| CVE-2023-39422 | Crítica (9.8) | 0.42% | — | 7 sept 2023 | The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering… |
| CVE-2023-39421 | Alta (7.7) | 0.47% | — | 7 sept 2023 | The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these… |
| CVE-2023-39420 | Alta (8.8) | 0.73% | — | 7 sept 2023 | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL… |