CVE-2023-47298

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:*

History

26 Jun 2025, 12:44

Type Values Removed Values Added
References () https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing - () https://drive.google.com/file/d/1-BDd0ycuYhuxo-lg4th-Cswimoqqzkot/view?usp=sharing - Permissions Required
References () https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md - () https://github.com/pwahba/cve-research/blob/main/CVE-2023-47298/CVE-2023-47298.md - Third Party Advisory
First Time Ncr terminal Handler
Ncr
CPE cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:*
Summary
  • (es) Un problema en NCR Terminal Handler 1.5.1 permite que un atacante autenticado con privilegios de bajo nivel consulte el endpoint de la API SOAP para obtener información sobre todos los usuarios de la aplicación, incluidos sus nombres de usuario, roles, grupos de seguridad y estados de cuenta.

24 Jun 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CWE CWE-200

23 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-23 15:15

Updated : 2025-06-26 12:44


NVD link : CVE-2023-47298

Mitre link : CVE-2023-47298

CVE.ORG link : CVE-2023-47298


JSON object : View

Products Affected

ncr

  • terminal_handler
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor