Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-47020

Опубликовано: 08 фев. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ncratleos:terminal_handler:1.5.1:*:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.00081
Низкий

8.8 High

CVSS3

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 8.8
github
почти 2 года назад

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

EPSS

Процентиль: 24%
0.00081
Низкий

8.8 High

CVSS3

Дефекты

CWE-352
CWE-352