An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.
References
Link | Resource |
---|---|
https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing | Permissions Required |
https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md | Third Party Advisory |
Configurations
History
26 Jun 2025, 12:44
Type | Values Removed | Values Added |
---|---|---|
First Time |
Ncr terminal Handler
Ncr |
|
Summary |
|
|
References | () https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing - Permissions Required | |
References | () https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md - Third Party Advisory | |
CPE | cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:* |
24 Jun 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-200 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
23 Jun 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-23 15:15
Updated : 2025-06-26 12:44
NVD link : CVE-2023-47298
Mitre link : CVE-2023-47298
CVE.ORG link : CVE-2023-47298
JSON object : View
Products Affected
ncr
- terminal_handler
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor