CVE-2023-47298

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
23/06/2025
Last modified:
26/06/2025

Description

An issue in NCR Terminal Handler 1.5.1 allows a low-level privileged authenticated attacker to query the SOAP API endpoint to obtain information about all of the users of the application including their usernames, roles, security groups and account statuses.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ncr:terminal_handler:1.5.1:*:*:*:*:*:*:*