Internet Reservation Module Next Generation
internet_reservation_module_next_generation
Vendor: Resortdata • 5 CVEs
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Resortdata 1Internet Reservation Module Next Generation Jun 17, 2026 Sep 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYST...Show more |
1Resortdata 1Internet Reservation Module Next Generation Jun 17, 2026 Sep 7, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions a...Show more |
1Resortdata 1Internet Reservation Module Next Generation Jun 17, 2026 Sep 7, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this...Show more |
1Resortdata 1Internet Reservation Module Next Generation Jun 17, 2026 Sep 7, 2023 N/A· v4 7.7 HIGH· v3 N/A· v2 The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these ser...Show more |
1Resortdata 1Internet Reservation Module Next Generation Jun 17, 2026 Sep 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL fi...Show more |