Known Vulnerabilities for products from Resortdata
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Resortdata".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-39424 json | A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to uplo... | 8.8 - HIGH | 2023-09-07 | 2023-09-12 |
| CVE-2023-39423 json | The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs, among other features. By using a U... | 9.1 - CRITICAL | 2023-09-07 | 2023-09-12 |
| CVE-2023-39422 json | The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. The... | 9.8 - CRITICAL | 2023-09-07 | 2023-09-12 |
| CVE-2023-39421 json | The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-par... | 7.7 - HIGH | 2023-09-07 | 2023-09-12 |
| CVE-2023-39420 json | The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers wit... | 8.8 - HIGH | 2023-09-07 | 2023-09-12 |