CVE-2023-47022

MEDIUM

NCR Terminal Handler <1.5.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639 CWE-1236
Status published
Products (1)
ncr/terminal_handler 1.5.1
Published Feb 06, 2024
Tracked Since Feb 18, 2026