PT-2024-13400 · Ncr · Ncr Terminal Handler
30T4
+1
·
Published
2024-01-19
·
Updated
2025-06-17
·
CVE-2023-47024
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NCR Terminal Handler version 1.5.1
Description
The issue is related to Cross-Site Request Forgery (CSRF) that can lead to a one-click account takeover. It is achieved by exploiting multiple vulnerabilities, including an undisclosed function in the WSDL that has weak security controls and can accept custom content types. A remote attacker can obtain sensitive information and escalate privileges via a crafted script to the
UserSelfService component.Recommendations
For NCR Terminal Handler version 1.5.1, consider disabling the
UserSelfService component until a patch is available to prevent exploitation. Restrict access to the WSDL function with weak security controls to minimize the risk of accepting custom content types. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ncr Terminal Handler