CVE-2023-47298

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:*

History

26 Jun 2025, 12:44

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-23 15:15

Updated : 2025-06-26 12:44


NVD link : CVE-2023-47298

Mitre link : CVE-2023-47298

CVE.ORG link : CVE-2023-47298


JSON object : View

Products Affected

ncr

  • terminal_handler
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor