The /irmdata/api/ endpoints exposed by the IRM Next...
Critical severity
Unreviewed
Published
Sep 7, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 7, 2023
Published to the GitHub Advisory Database
Sep 7, 2023
Last updated
Apr 4, 2024
The /irmdata/api/ endpoints exposed by the IRM Next Generation booking engine authenticates requests using HMAC tokens. These tokens are however exposed in a JavaScript file loaded on the client side, thus rendering this extra safety mechanism useless.
References