ZeroHour

CVE-2023-47022

CVSS 3.1
6.5 medium
EPSS
<1%p27
Published
()
Modified
Description

Insecure Direct Object Reference in NCR Terminal Handler v.1.5.1 allows an unprivileged user to edit the audit logs for any user and can lead to CSV injection.

Vendors
ncr
Products
terminal handler
Weakness
CWE-639, CWE-1236
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.