Vulnerability CVE-2023-39421


Published: 2023-09-07

Description:
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.

Type:

CWE-798

 References:
https://bitdefender.com/blog/labs/check-out-with-extra-charges-vulnerabilities-in-hotel-booking-engine-explained

Copyright 2026, cxsecurity.com

 

Back to Top