Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.
References
Link | Resource |
---|---|
https://github.com/Patrick0x41/Security-Advisories/tree/main/CVE-2023-47020 | Third Party Advisory |
https://youtu.be/pGB3LKdf64w | Exploit |
https://github.com/Patrick0x41/Security-Advisories/tree/main/CVE-2023-47020 | Third Party Advisory |
https://youtu.be/pGB3LKdf64w | Exploit |
Configurations
History
21 Nov 2024, 08:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Patrick0x41/Security-Advisories/tree/main/CVE-2023-47020 - Third Party Advisory | |
References | () https://youtu.be/pGB3LKdf64w - Exploit |
15 Feb 2024, 03:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-352 | |
First Time |
Ncratleos terminal Handler
Ncratleos |
|
References | () https://github.com/Patrick0x41/Security-Advisories/tree/main/CVE-2023-47020 - Third Party Advisory | |
References | () https://youtu.be/pGB3LKdf64w - Exploit | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:ncratleos:terminal_handler:1.5.1:*:*:*:*:*:*:* |
08 Feb 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-08 16:15
Updated : 2024-11-21 08:29
NVD link : CVE-2023-47020
Mitre link : CVE-2023-47020
CVE.ORG link : CVE-2023-47020
JSON object : View
Products Affected
ncratleos
- terminal_handler
CWE
CWE-352
Cross-Site Request Forgery (CSRF)