PT-2024-13399 · Ncr · Ncr Terminal Handler
30T4
+1
·
Published
2024-02-05
·
Updated
2025-06-17
·
CVE-2023-47022
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
NCR Terminal Handler version 1.5.1
Description
The issue allows an unprivileged user to edit the audit logs for any user, potentially leading to CSV injection. It also enables a remote attacker to execute arbitrary code via a crafted script to the
payload parameter.Recommendations
For NCR Terminal Handler version 1.5.1, consider restricting access to the audit logs and limiting the ability to edit them until a patch is available. As a temporary workaround, avoid using the
payload parameter in affected API endpoints until the issue is resolved.Exploit
Fix
IDOR
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ncr Terminal Handler