Vulnerability Description
Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed function in the WSDL that has weak security controls and can accept custom content types.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ncratleos | Terminal Handler | 1.5.1 |
Related Weaknesses (CWE)
References
- https://docs.google.com/document/d/18EOsFghBsAme0b3Obur8Oc6h5xV9zUCNKyQLw5ERs9Q/Permissions Required
- https://github.com/Patrick0x41/Security-Advisories/tree/main/CVE-2023-47024Third Party Advisory
- https://docs.google.com/document/d/18EOsFghBsAme0b3Obur8Oc6h5xV9zUCNKyQLw5ERs9Q/Permissions Required
- https://github.com/Patrick0x41/Security-Advisories/tree/main/CVE-2023-47024Third Party Advisory
FAQ
What is CVE-2023-47024?
CVE-2023-47024 is a vulnerability with a CVSS score of 8.8 (HIGH). Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed function in t...
How severe is CVE-2023-47024?
CVE-2023-47024 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-47024?
Check the references section above for vendor advisories and patch information. Affected products include: Ncratleos Terminal Handler.