CVE-2023-47298

A

n issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.

Configurations

Configuration 1 (hide)

cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:*

History

26 Jun 2025, 12:44

Type Values Removed Values Added
CPE cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:*
First Time Ncr
Ncr terminal Handler
Summary
  • (es) Un problema en NCR Terminal Handler 1.5.1 permite que un atacante autenticado con privilegios de bajo nivel consulte el endpoint de la API SOAP para obtener información sobre todos los usuarios de la aplicación, incluidos sus nombres de usuario, roles, grupos de seguridad y estados de cuenta.
References () https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing - () https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing - Permissions Required
References () https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md - () https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md - Third Party Advisory

24 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3

23 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-23 15:15

Updated : 2025-06-26 12:44


NVD link : CVE-2023-47298

Mitre link : CVE-2023-47298

CVE.ORG link : CVE-2023-47298


JSON object : View

Products Affected
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor