Логотип exploitDog
bind:CVE-2023-47020
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-47020

Количество 2

Количество 2

nvd логотип

CVE-2023-47020

около 2 лет назад

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-gw6h-pq4q-jjr4

около 2 лет назад

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-47020

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

CVSS3: 8.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-gw6h-pq4q-jjr4

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed function in the WSDL that lacks security controls and can accept custom content types.

CVSS3: 8.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу