The /irmdata/api/ endpoints exposed... CVE-2023-39422

- AV AC AU C I A
发布: 2023-09-07
修订: 2023-09-12

The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息