CVE-2023-47298

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:*

History

26 Jun 2025, 12:44

Type Values Removed Values Added
First Time Ncr terminal Handler
Ncr
Summary
  • (es) Un problema en NCR Terminal Handler 1.5.1 permite que un atacante autenticado con privilegios de bajo nivel consulte el endpoint de la API SOAP para obtener información sobre todos los usuarios de la aplicación, incluidos sus nombres de usuario, roles, grupos de seguridad y estados de cuenta.
References () https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing - () https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing - Permissions Required
References () https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md - () https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md - Third Party Advisory
CPE cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:*

24 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

23 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-23 15:15

Updated : 2025-06-26 12:44


NVD link : CVE-2023-47298

Mitre link : CVE-2023-47298

CVE.ORG link : CVE-2023-47298


JSON object : View

Products Affected

ncr

  • terminal_handler
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor