CVE-2023-47022

Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-06 01:15

Updated : 2024-02-13 18:14


NVD link : CVE-2023-47022

Mitre link : CVE-2023-47022

CVE.ORG link : CVE-2023-47022


JSON object : View

Products Affected

ncr

  • terminal_handler
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File

CWE-639

Authorization Bypass Through User-Controlled Key